{
 "id": "WPSEC-2026-0711",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0711/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0711/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0711/index.md",
 "title": "LifterLMS <= 10.3.0 - Unauthenticated Sensitive Information Exposure via Certificate oEmbed and Canonical Redirects",
 "description": "The LifterLMS plugin for WordPress is vulnerable to Sensitive Information Exposure via the oEmbed endpoint and canonical redirects for awarded certificates in all versions up to, and including, 10.3.0. The plugin's 404 handling for private awarded certificates ran only on regular front-end views, so it did not apply to oEmbed responses or canonical redirects. This makes it possible for unauthenticated attackers to look up private awarded certificates by post ID and retrieve their title, recipient (author) name and permalink.",
 "plugin": {
  "slug": "lifterlms",
  "name": "LifterLMS",
  "full_name": "LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes",
  "wordpress_org": "https://wordpress.org/plugins/lifterlms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/lifterlms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/lifterlms"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "10.3.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 10.3.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "10.3.1",
 "remediation": "Update to 10.3.1 or later.",
 "fix_released": "2026-10-08T13:02:22+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:29.650561+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0711/",
  "https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/",
  "https://wordpress.org/plugins/lifterlms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/lifterlms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}