Impact
The LifterLMS plugin for WordPress, versions up to 9.2.1, contains an SQL injection flaw in the 'order' parameter used by quiz reporting tables. Because the value is not properly sanitized or parameterized, an attacker who can edit a quiz can inject arbitrary SQL, allowing extraction of sensitive database contents such as user data or quiz statistics. The flaw does not directly modify or delete data but compromises confidentiality.
Affected Systems
All WordPress sites that have the LifterLMS plugin installed from the vendor chrisbadgett, specifically the WP LMS for eLearning, Online Courses, & Quizzes, are affected when the plugin version is 9.2.1 or older. Sites using later versions are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The vulnerability is not listed in CISA KEV and has no EPSS score available. Exploitation requires authentication with at least instructor-level privileges and the edit_post capability on a quiz, limiting the attack surface. Successful exploitation would compromise database confidentiality, while integrity and availability remain unaffected, so overall risk is moderate but constrained by the privilege requirement.
OpenCVE Enrichment