Vulnerabilities / LifterLMS / WPSEC-2026-0710

LifterLMS <= 10.3.0 - Authentication Bypass via REST API Key Route Restriction

Medium 5.4 CWE-287Fixed in 10.3.1
ID
WPSEC-2026-0710
Plugin
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
Affected
all versions before 10.3.1
Remediation
Update to 10.3.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
LifterLMS on WPSec AttackSurface
Fix released
Published

Description

The LifterLMS plugin for WordPress is vulnerable to an authentication restriction bypass in all versions up to, and including, 10.3.0. The REST API key authentication decided whether a request targeted a LifterLMS route by reading the request path. WordPress, however, serves the route given in a 'rest_route' request argument, which takes precedence over the path. This makes it possible for holders of LifterLMS API key credentials to authenticate requests to non-LifterLMS WordPress REST API routes as the user the key belongs to, beyond the intended scope of the key.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0