Description
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via deserialization of untrusted input . This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. This vulnerability is only exploitable during lesson creation when a temporary lesson ID triggers the custom metadata path, and requires the attacker to hold a role with the edit_course capability, such as Instructor, Instructor's Assistant, LMS Manager, or Administrator.
Published: 2026-10-10
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Authenticated PHP Object Injection with potential Remote Code Execution if a POP chain exists
Action: Immediate Patch
AI Analysis

Impact

The LifterLMS WordPress plugin up to and including version 10.2.1 deserializes untrusted input from custom lesson data without proper validation, allowing an authenticated attacker with a role that has the edit_course capability to inject a PHP Object. The plugin itself does not contain a PHP Object Property (POP) chain, so the injected object has no immediate effect. However, if the site hosts another plugin or theme that supplies a compatible POPT chain, the attacker could delete files, access sensitive information, or execute arbitrary code.

Affected Systems

Affected systems are WordPress installations using the LifterLMS plugin at or below version 10.2.1. The vulnerability is only reachable by users who can create or edit courses, such as Instructors, Instructors' Assistants, LMS Managers, or Administrators, and only when a temporary lesson ID triggers the custom metadata path during lesson creation.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8 and is not currently listed in the CISA KEV catalog. The EPSS score is unavailable, but the absence of an inbuilt POP chain reduces the likelihood of successful exploitation unless a third‑party plugin or theme provides one. Attackers would need to exploit the deserialization flaw through the lesson creation interface and then rely on a separate component to execute a malicious PHP object chain. While the potential impact is high—allowing arbitrary code execution or file deletion—the overall risk is mitigated by the necessity of a second element for abuse.

Generated by OpenCVE AI on October 10, 2026 at 06:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the LifterLMS plugin to version 10.2.2 or later, which removes the vulnerable deserialization of custom lesson data.
  • Audit the WordPress installation for other plugins or themes that include PHP Object Property chains and either upgrade them to secure versions or remove the risky components.
  • Limit the number of users with edit_course capability during the remediation period, or temporarily disable access to the lesson creation API for those roles until the fix is applied.

Generated by OpenCVE AI on October 10, 2026 at 06:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via deserialization of untrusted input . This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. This vulnerability is only exploitable during lesson creation when a temporary lesson ID triggers the custom metadata path, and requires the attacker to hold a role with the edit_course capability, such as Instructor, Instructor's Assistant, LMS Manager, or Administrator.
Title LifterLMS <= 10.2.1 - Authenticated (Custom+) PHP Object Injection via 'custom' Lesson Data
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:31:04.327Z

Reserved: 2026-10-02T11:45:07.720Z

Link: CVE-2026-104723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:38.760

Modified: 2026-10-10T06:16:38.760

Link: CVE-2026-104723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:30:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data