Product
The LifterLMS WordPress plugin is vulnerable to authenticated PHP Object Injection, allowing attackers with edit_course capabilities to potentially execute code if a compatible POP chain exists elsewhere in the environment.