πŸ” CVE Alert

CVE-2026-14231

MEDIUM 4.3

LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts

CVSS Score
4.3
EPSS Score
0.2%
EPSS Percentile
5th

The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.

Vendor unknown
Product lifterlms
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown lifterlms

Be the first to know when new medium vulnerabilities affecting unknown lifterlms are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Unknown / LifterLMS
0 < 10.0.10

References

NVD β†— CVE.org β†— EPSS Data β†—
wpscan.com: https://wpscan.com/vulnerability/2a353964-9f4c-4528-b187-42766f0cfaed/

Credits

Daniel PΓΊa - devploit WPScan