Vulnerabilities / LifterLMS / WPSEC-2026-0713

LifterLMS <= 10.3.0 - Unauthenticated Insecure Direct Object Reference to Pending Order Takeover via Checkout

Medium 6.5 CWE-639Fixed in 10.3.1
ID
WPSEC-2026-0713
Plugin
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
Affected
from 7.0.0 before 10.3.1
Remediation
Update to 10.3.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
LifterLMS on WPSec AttackSurface
Fix released
Published

Description

The LifterLMS plugin for WordPress is vulnerable to Insecure Direct Object Reference via the checkout order handlers in all versions up to, and including, 10.3.0, due to the checkout order lookup not verifying who owns the order. During AJAX checkout an existing pending order was located only from the billing email address submitted with the request. The checkout handlers also accepted a submitted order key for any order, whatever its status or owner. This makes it possible for unauthenticated attackers to take over another customer's pending order for an access plan by knowing that customer's email address. They can overwrite its billing details and plan data and receive the order's key in the response.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0