# LifterLMS <= 10.3.0 - Unauthenticated Sensitive Information Exposure via Certificate oEmbed and Canonical Redirects

- **ID:** WPSEC-2026-0711
- **Plugin:** LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (`lifterlms`), https://wordpress.org/plugins/lifterlms/
- **Affected versions:** all versions before 10.3.1
- **Fixed in:** 10.3.1 (Update to 10.3.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/lifterlms
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0711/

## Description

The LifterLMS plugin for WordPress is vulnerable to Sensitive Information Exposure via the oEmbed endpoint and canonical redirects for awarded certificates in all versions up to, and including, 10.3.0. The plugin's 404 handling for private awarded certificates ran only on regular front-end views, so it did not apply to oEmbed responses or canonical redirects. This makes it possible for unauthenticated attackers to look up private awarded certificates by post ID and retrieve their title, recipient (author) name and permalink.

## References

- https://wpsec.com/vuln/WPSEC-2026-0711/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/
- https://wordpress.org/plugins/lifterlms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0711/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
