Home/Product/lifterlms
Product

lifterlms

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-52717
< 8.0.7
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett LifterLMS lifte
9.3CRITICAL
CVE-2024-13619
< 8.0.1
The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leadi
6.1MEDIUM
CVE-2025-2290
< 8.0.2
The LifterLMS - WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashin
5.3MEDIUM
CVE-2024-12596
< 7.8.6
The LifterLMS - WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due
4.3MEDIUM
CVE-2024-7349
< 7.7.6
The LifterLMS - WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the
7.2HIGH
CVE-2024-4743
< 7.6.3
The LifterLMS - WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attribute o
8.8HIGH
CVE-2024-31363
< 7.5.1
Cross-Site Request Forgery (CSRF) vulnerability in LifterLMS.This issue affects LifterLMS: from n/a through 7.5.0.
4.3MEDIUM
CVE-2024-0377
< 7.5.2
The LifterLMS - WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to
5.3MEDIUM
CVE-2023-6160
<= 7.4.2
The LifterLMS - WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, an
3.3LOW
CVE-2022-1250
< 1.4.0
The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page
6.1MEDIUM
CVE-2021-24562
< 4.21.2
The LMS by LifterLMS - Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affect
7.5HIGH
CVE-2021-24308
< 4.21.1
The 'State' field of the Edit profile page of the LMS by LifterLMS - Online Course, Membership & Learning Management System Plugin
5.4MEDIUM
CVE-2020-6008
< 3.37.15
LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
9.8CRITICAL
CVE-2019-15896
<= 3.34.5
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.i
9.8CRITICAL
threatengine.sh