Extension WordPress
Vulnérabilités LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
Cette page rassemble les failles publiées pour LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
16 fiches
LifterLMS <= 9.2.1 – Authenticated (Custom+) SQL Injection via 'order' Parameter
The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 9.2.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-9.2.1
9.2.2
10/04/2026
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes – Various Versions – Authenticated (Student+) Privilege Escalation
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin not properly validating a user's identity prior to allowing them to modify their…
3.5.3-3.41.1, 4.0.0-4.21.3, 5.0.0-5.10.0, 6.0.0-6.11.0, 7.0.0-7.8.7, 8.0.0-8.0.7, 9.0.0-9.0.7, 9.1.0
3.41.2, 4.21.4, 5.10.1, 6.11.1, 7.8.8, 8.0.8, 9.0.8, 9.1.1
12/11/2025
LifterLMS <= 8.0.6 – Unauthenticated SQL Injection
The LifterLMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-8.0.6
8.0.7
01/07/2025
LifterLMS <= 8.0.1 – Missing Authorization to Unauthenticated Post Trashing
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions…
*-8.0.1
8.0.2
18/03/2025
LifterLMS <= 8.0.0 – Reflected Cross-Site Scripting
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 8.0.0 due to insufficient input sanitization and output escaping. This makes…
*-8.0.0
8.0.1
03/03/2025
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5.…
*-7.8.5
7.8.6
17/12/2024
LifterLMS <= 7.7.5 – Authenticated (Admin+) SQL Injection
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to insufficient escaping on the…
*-7.7.5
7.7.6
05/09/2024
LifterLMS – WordPress LMS Plugin for eLearning <= 7.6.2 – Authenticated (Contributor+) SQL Injection via Shortcode
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attribute of the lifterlms_favorites shortcode in all versions up to, and including, 7.6.2 due to insufficient escaping on the…
*-7.6.2
7.6.3
04/06/2024
LifterLMS <= 7.5.0 – Cross-Site Request Forgery
The LifterLMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.0. This is due to missing or incorrect nonce validation on the llms-clone-post action. This makes it possible for unauthenticated attackers…
*-7.5.0
7.5.1
08/04/2024
LifterLMS – WordPress LMS Plugin for eLearning <= 7.5.1 – Missing Authorization via process_review
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_review' function in all versions up to, and including, 7.5.1. This makes…
*-7.5.1
7.5.2
27/02/2024
LifterLMS <= 7.4.2 – Authenticated(Administrator+) Directory Traversal to Arbitrary CSV File Deletion
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 via the maybe_serve_export function. This makes it possible for authenticated attackers, with administrator or LMS…
*-7.4.2
7.5.0
05/11/2023
LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress < 4.21.2 – Insecure Direct Object Reference
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
[*, 4.21.2)
4.21.2
17/05/2021
LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin <= 4.21.0 – Stored Cross-Site Scripting
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of…
[*, 4.21.1)
4.21.1
10/05/2021
LMS by LifterLMS <= 4.21.0 – Reflected Cross-Site Scripting
The LMS by LifterLMS plugin for WordPress has a reflected cross-site scripting vulnerability in the in versions up to, and including, 4.21.0 due to insufficient input sanitization and output escaping on the 'coupon_code' parameter. This makes it possible…
[*, 4.21.1)
4.21.1
29/04/2021
LifterLMS Wordpress Plugin <= 3.37.14 – Arbitrary File Write
LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution.
[*, 3.37.15)
3.37.15
31/03/2020
LMS by LifterLMS <= 3.35.0 – Stored Cross-Site Scripting via Import
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection,…
[*, 3.35.0)
3.35.0
09/09/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.