{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lifterlms--wp-lms-for-elearning-online-courses--quizzes--10.2.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lifterlms:lifterlms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-104723"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LifterLMS – WP LMS for eLearning, Online Courses, \u0026 Quizzes (\u003c= 10.2.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LifterLMS"],"content_html":"\u003cp\u003eThe LifterLMS plugin for WordPress, in versions up to and including 10.2.1, contains an insecure deserialization vulnerability identified as CVE-2026-104723. The vulnerability exists within the lesson creation process, where the plugin improperly handles untrusted input during the metadata processing phase. To exploit this, an attacker must possess an account with at least 'edit_course' capabilities, such as an Instructor or LMS Manager.\u003c/p\u003e\n\u003cp\u003eWhile the LifterLMS codebase itself does not contain a Property-Oriented Programming (POP) chain, the vulnerability allows an attacker to inject arbitrary PHP objects that can be exploited if other plugins or themes installed on the same WordPress instance provide the necessary gadgets. Successful exploitation, in conjunction with a separate vulnerable component, may lead to arbitrary file deletion, unauthorized data retrieval, or remote code execution. This highlights the risk posed by the aggregate attack surface of complex CMS environments where multiple plugins interact.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of this vulnerability is contingent upon the presence of auxiliary POP chains within the WordPress environment. If a chain is present, an attacker could achieve full site compromise, execute remote code, or modify sensitive system files. The vulnerability specifically targets environments using LifterLMS for course management, exposing educational institutions and online training platforms to potential data breaches and service disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade LifterLMS to a version beyond 10.2.1 immediately to resolve the underlying deserialization flaw.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress environment for unused plugins or themes, as these may contain POP chains that could be leveraged by this vulnerability.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege by reviewing user roles and stripping 'edit_course' capabilities from any accounts that do not strictly require them for course administration.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to monitor for suspicious POST requests containing serialized PHP objects directed at lesson creation endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:50:43Z","date_published":"2026-10-10T07:50:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-lifterlms-rce/","summary":"The LifterLMS WordPress plugin is vulnerable to authenticated PHP Object Injection, allowing attackers with edit_course capabilities to potentially execute code if a compatible POP chain exists elsewhere in the environment.","title":"PHP Object Injection Vulnerability in LifterLMS Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-lifterlms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - LifterLMS – WP LMS for ELearning, Online Courses, \u0026 Quizzes (\u003c= 10.2.1)","version":"https://jsonfeed.org/version/1.1"}