Vulnerabilities / LifterLMS / WPSEC-2026-0712

LifterLMS <= 10.3.0 - Authenticated (Subscriber+) CSV Injection via Reporting Exports

Medium 4.6 CWE-1236Fixed in 10.3.1
ID
WPSEC-2026-0712
Plugin
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
Affected
all versions before 10.3.1
Remediation
Update to 10.3.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Weakness
CWE-1236
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
LifterLMS on WPSec AttackSurface
Fix released
Published

Description

The LifterLMS plugin for WordPress is vulnerable to CSV Injection via the reporting table exports in all versions up to, and including, 10.3.0, due to cell values not being neutralized before they are written to the export file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to put spreadsheet formulas in their profile fields (such as first name, last name or billing address). The formulas are written into exports that an administrator downloads and run when the file is opened in a spreadsheet application.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0