Impact
The LifterLMS WordPress plugin up to and including version 10.2.1 deserializes untrusted input from custom lesson data without proper validation, allowing an authenticated attacker with a role that has the edit_course capability to inject a PHP Object. The plugin itself does not contain a PHP Object Property (POP) chain, so the injected object has no immediate effect. However, if the site hosts another plugin or theme that supplies a compatible POPT chain, the attacker could delete files, access sensitive information, or execute arbitrary code.
Affected Systems
Affected systems are WordPress installations using the LifterLMS plugin at or below version 10.2.1. The vulnerability is only reachable by users who can create or edit courses, such as Instructors, Instructors' Assistants, LMS Managers, or Administrators, and only when a temporary lesson ID triggers the custom metadata path during lesson creation.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8 and is not currently listed in the CISA KEV catalog. The EPSS score is unavailable, but the absence of an inbuilt POP chain reduces the likelihood of successful exploitation unless a third‑party plugin or theme provides one. Attackers would need to exploit the deserialization flaw through the lesson creation interface and then rely on a separate component to execute a malicious PHP object chain. While the potential impact is high—allowing arbitrary code execution or file deletion—the overall risk is mitigated by the necessity of a second element for abuse.
OpenCVE Enrichment