# LifterLMS <= 10.3.0 - Unauthenticated Insecure Direct Object Reference to Pending Order Takeover via Checkout

- **ID:** WPSEC-2026-0713
- **Plugin:** LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (`lifterlms`), https://wordpress.org/plugins/lifterlms/
- **Affected versions:** from 7.0.0 before 10.3.1
- **Fixed in:** 10.3.1 (Update to 10.3.1 or later.)
- **Severity:** Medium 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/lifterlms
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0713/

## Description

The LifterLMS plugin for WordPress is vulnerable to Insecure Direct Object Reference via the checkout order handlers in all versions up to, and including, 10.3.0, due to the checkout order lookup not verifying who owns the order. During AJAX checkout an existing pending order was located only from the billing email address submitted with the request. The checkout handlers also accepted a submitted order key for any order, whatever its status or owner. This makes it possible for unauthenticated attackers to take over another customer's pending order for an access plan by knowing that customer's email address. They can overwrite its billing details and plan data and receive the order's key in the response.

## References

- https://wpsec.com/vuln/WPSEC-2026-0713/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/
- https://wordpress.org/plugins/lifterlms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0713/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
