Vulnerabilities / LifterLMS / WPSEC-2026-0711
LifterLMS <= 10.3.0 - Unauthenticated Sensitive Information Exposure via Certificate oEmbed and Canonical Redirects
Medium 5.3
CWE-200Fixed in 10.3.1
- ID
- WPSEC-2026-0711
- Plugin
- LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
- Affected
- all versions before 10.3.1
- Remediation
- Update to 10.3.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- LifterLMS on WPSec AttackSurface
- Fix released
- Published
Description
The LifterLMS plugin for WordPress is vulnerable to Sensitive Information Exposure via the oEmbed endpoint and canonical redirects for awarded certificates in all versions up to, and including, 10.3.0. The plugin's 404 handling for private awarded certificates ran only on regular front-end views, so it did not apply to oEmbed responses or canonical redirects. This makes it possible for unauthenticated attackers to look up private awarded certificates by post ID and retrieve their title, recipient (author) name and permalink.
References
- https://wpsec.com/vuln/WPSEC-2026-0711/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/
- https://wordpress.org/plugins/lifterlms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS