LifterLMS <= 10.3.0 - Unauthenticated Insecure Direct Object Reference to Pending Order Takeover via Checkout
- ID
- WPSEC-2026-0713
- Plugin
- LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
- Affected
- from 7.0.0 before 10.3.1
- Remediation
- Update to 10.3.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- LifterLMS on WPSec AttackSurface
- Fix released
- Published
Description
The LifterLMS plugin for WordPress is vulnerable to Insecure Direct Object Reference via the checkout order handlers in all versions up to, and including, 10.3.0, due to the checkout order lookup not verifying who owns the order. During AJAX checkout an existing pending order was located only from the billing email address submitted with the request. The checkout handlers also accepted a submitted order key for any order, whatever its status or owner. This makes it possible for unauthenticated attackers to take over another customer's pending order for an access plan by knowing that customer's email address. They can overwrite its billing details and plan data and receive the order's key in the response.
References
- https://wpsec.com/vuln/WPSEC-2026-0713/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/
- https://wordpress.org/plugins/lifterlms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS