Impact
The LifterLMS WordPress plugin contains a missing capability check that permits any unauthenticated user to trigger the delete_access_plan AJAX routine, which moves every published post to the Trash folder. This flaw is identified as CWE‑862. The effect is a denial of service or content loss, compromising the availability of a website’s learning materials.
Affected Systems
Versions of the LifterLMS plugin published by Chris Badgett for WordPress, up to and including 8.0.1, are affected. Newer releases are assumed to contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS probability is below 1%, suggesting limited exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Attackers would use unauthenticated AJAX calls to trigger deletion, meaning no user credential is required. Despite the low current exploitation likelihood, the impact on content availability warrants prompt remediation.
OpenCVE Enrichment
EUVD