# LifterLMS <= 10.3.0 - Authenticated (Subscriber+) CSV Injection via Reporting Exports

- **ID:** WPSEC-2026-0712
- **Plugin:** LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (`lifterlms`), https://wordpress.org/plugins/lifterlms/
- **Affected versions:** all versions before 10.3.1
- **Fixed in:** 10.3.1 (Update to 10.3.1 or later.)
- **Severity:** Medium 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-1236
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/lifterlms
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0712/

## Description

The LifterLMS plugin for WordPress is vulnerable to CSV Injection via the reporting table exports in all versions up to, and including, 10.3.0, due to cell values not being neutralized before they are written to the export file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to put spreadsheet formulas in their profile fields (such as first name, last name or billing address). The formulas are written into exports that an administrator downloads and run when the file is opened in a spreadsheet application.

## References

- https://wpsec.com/vuln/WPSEC-2026-0712/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/
- https://wordpress.org/plugins/lifterlms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0712/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
