{
 "id": "WPSEC-2026-0712",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0712/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0712/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0712/index.md",
 "title": "LifterLMS <= 10.3.0 - Authenticated (Subscriber+) CSV Injection via Reporting Exports",
 "description": "The LifterLMS plugin for WordPress is vulnerable to CSV Injection via the reporting table exports in all versions up to, and including, 10.3.0, due to cell values not being neutralized before they are written to the export file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to put spreadsheet formulas in their profile fields (such as first name, last name or billing address). The formulas are written into exports that an administrator downloads and run when the file is opened in a spreadsheet application.",
 "plugin": {
  "slug": "lifterlms",
  "name": "LifterLMS",
  "full_name": "LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes",
  "wordpress_org": "https://wordpress.org/plugins/lifterlms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/lifterlms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/lifterlms"
 },
 "type": "CSV INJECTION",
 "cwe": [
  "CWE-1236"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.6,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "10.3.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 10.3.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "10.3.1",
 "remediation": "Update to 10.3.1 or later.",
 "fix_released": "2026-10-08T13:02:22+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:29.650561+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0712/",
  "https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/",
  "https://wordpress.org/plugins/lifterlms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/lifterlms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}