LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
lifterlms · plugin
Known security vulnerabilities for LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes. Find out in seconds which version runs on your site with WP Lens.
11 known vulnerabilities
3 critical · 1 with public exploit code · latest Apr 10, 2026
Vulnerabilities
- Critical 9.8
WordPress LifterLMS plugin <= 8.0.6 - SQL Injection Vulnerability
- Critical 9.8
LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
- Critical 9.8
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress.
- High 8.8
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Student+) Privilege Escalation
- High 8.8
LifterLMS – WordPress LMS Plugin for eLearning <= 7.6.2 - Authenticated (Contributor+) SQL Injection via Shortcode
- High 8.8
WordPress LifterLMS plugin <= 7.5.0 - Cross Site Request Forgery (CSRF) vulnerability
- High 7.2
LifterLMS <= 7.7.5 - Authenticated (Admin+) SQL Injection
- Medium 6.5
LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter
- Medium 5.3
LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing
- Medium 5.3
LifterLMS – WordPress LMS Plugin for eLearning <= 7.5.1 - Missing Authorization via process_review
- Medium 4.3
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion