{
 "id": "WPSEC-2026-0713",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0713/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0713/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0713/index.md",
 "title": "LifterLMS <= 10.3.0 - Unauthenticated Insecure Direct Object Reference to Pending Order Takeover via Checkout",
 "description": "The LifterLMS plugin for WordPress is vulnerable to Insecure Direct Object Reference via the checkout order handlers in all versions up to, and including, 10.3.0, due to the checkout order lookup not verifying who owns the order. During AJAX checkout an existing pending order was located only from the billing email address submitted with the request. The checkout handlers also accepted a submitted order key for any order, whatever its status or owner. This makes it possible for unauthenticated attackers to take over another customer's pending order for an access plan by knowing that customer's email address. They can overwrite its billing details and plan data and receive the order's key in the response.",
 "plugin": {
  "slug": "lifterlms",
  "name": "LifterLMS",
  "full_name": "LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes",
  "wordpress_org": "https://wordpress.org/plugins/lifterlms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/lifterlms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/lifterlms"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "7.0.0",
    "from_inclusive": true,
    "to": "10.3.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 7.0.0 before 10.3.1"
  ]
 },
 "introduced_in": "7.0.0",
 "fixed_in": "10.3.1",
 "remediation": "Update to 10.3.1 or later.",
 "fix_released": "2026-10-08T13:02:22+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:29.650561+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0713/",
  "https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/",
  "https://wordpress.org/plugins/lifterlms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/lifterlms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}