Vulnerabilities / LifterLMS / WPSEC-2026-0715

LifterLMS <= 10.3.0 - Unauthenticated Deleted Access Plan Purchase via Checkout

Medium 5.3 CWE-284Fixed in 10.3.1
ID
WPSEC-2026-0715
Plugin
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
Affected
all versions before 10.3.1
Remediation
Update to 10.3.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-284
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
LifterLMS on WPSec AttackSurface
Fix released
Published

Description

The LifterLMS plugin for WordPress is vulnerable to an access restriction bypass via the checkout handlers in all versions up to, and including, 10.3.0, due to the purchasability check not verifying that the submitted access plan is published. Deleting an access plan only moves it to the trash. This makes it possible for unauthenticated attackers to check out with a deleted (trashed) access plan by submitting its ID, for example to enroll in a course or membership at the price or free terms of a plan the site owner removed.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0