CVE-2026-14231
LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts
CVSS Score
4.3
EPSS Score
0.2%
EPSS Percentile
5th
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.
| Vendor | unknown |
| Product | lifterlms |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown lifterlms
Be the first to know when new medium vulnerabilities affecting unknown lifterlms are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Unknown / LifterLMS
0 < 10.0.10
References
Credits
Daniel PΓΊa - devploit WPScan