CVE-2026-14207
LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course.
| Vendor | unknown |
| Product | lifterlms |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown lifterlms
Be the first to know when new medium vulnerabilities affecting unknown lifterlms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / LifterLMS
9.2.3 < 10.0.10
References
Credits
Mustafa Ahmed WPScan