# LifterLMS <= 10.3.0 - Unauthenticated Deleted Access Plan Purchase via Checkout

- **ID:** WPSEC-2026-0715
- **Plugin:** LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (`lifterlms`), https://wordpress.org/plugins/lifterlms/
- **Affected versions:** all versions before 10.3.1
- **Fixed in:** 10.3.1 (Update to 10.3.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-284
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/lifterlms
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0715/

## Description

The LifterLMS plugin for WordPress is vulnerable to an access restriction bypass via the checkout handlers in all versions up to, and including, 10.3.0, due to the purchasability check not verifying that the submitted access plan is published. Deleting an access plan only moves it to the trash. This makes it possible for unauthenticated attackers to check out with a deleted (trashed) access plan by submitting its ID, for example to enroll in a course or membership at the price or free terms of a plan the site owner removed.

## References

- https://wpsec.com/vuln/WPSEC-2026-0715/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.1/
- https://wordpress.org/plugins/lifterlms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0715/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
