Skip to content
Noroxi

LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes

lifterlms · plugin

Known security vulnerabilities for LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes. Find out in seconds which version runs on your site with WP Lens.

11 known vulnerabilities

3 critical · 1 with public exploit code · latest Apr 10, 2026

Vulnerabilities

  • CVE-2025-52717

    WordPress LifterLMS plugin <= 8.0.6 - SQL Injection Vulnerability

    Critical 9.8
  • CVE-2020-6008

    LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

    Critical 9.8
  • CVE-2019-15896

    An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress.

    Critical 9.8
  • CVE-2025-11923

    LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Student+) Privilege Escalation

    High 8.8
  • CVE-2024-4743

    LifterLMS – WordPress LMS Plugin for eLearning <= 7.6.2 - Authenticated (Contributor+) SQL Injection via Shortcode

    High 8.8
  • CVE-2024-31363

    WordPress LifterLMS plugin <= 7.5.0 - Cross Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2024-7349

    LifterLMS <= 7.7.5 - Authenticated (Admin+) SQL Injection

    High 7.2
  • CVE-2026-5207

    LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter

    Medium 6.5
  • CVE-2025-2290

    LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing

    Medium 5.3
  • CVE-2024-0377

    LifterLMS – WordPress LMS Plugin for eLearning <= 7.5.1 - Missing Authorization via process_review

    Medium 5.3
  • CVE-2024-12596

    LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion

    Medium 4.3

← Back to directory