Vulnerabilities / LifterLMS / WPSEC-2026-0712
LifterLMS <= 10.3.0 - Authenticated (Subscriber+) CSV Injection via Reporting Exports
Medium 4.6
CWE-1236Fixed in 10.3.1
- ID
- WPSEC-2026-0712
- Plugin
- LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
- Affected
- all versions before 10.3.1
- Remediation
- Update to 10.3.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- Weakness
- CWE-1236
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- LifterLMS on WPSec AttackSurface
- Fix released
- Published
Description
The LifterLMS plugin for WordPress is vulnerable to CSV Injection via the reporting table exports in all versions up to, and including, 10.3.0, due to cell values not being neutralized before they are written to the export file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to put spreadsheet formulas in their profile fields (such as first name, last name or billing address). The formulas are written into exports that an administrator downloads and run when the file is opened in a spreadsheet application.
References
- https://wpsec.com/vuln/WPSEC-2026-0712/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/
- https://wordpress.org/plugins/lifterlms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS