<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>LifterLMS – WP LMS for ELearning, Online Courses, &amp; Quizzes (&lt;= 10.2.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/lifterlms--wp-lms-for-elearning-online-courses--quizzes--10.2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:50:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/lifterlms--wp-lms-for-elearning-online-courses--quizzes--10.2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PHP Object Injection Vulnerability in LifterLMS Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-lifterlms-rce/</link><pubDate>Sat, 10 Oct 2026 07:50:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-lifterlms-rce/</guid><description>The LifterLMS WordPress plugin is vulnerable to authenticated PHP Object Injection, allowing attackers with edit_course capabilities to potentially execute code if a compatible POP chain exists elsewhere in the environment.</description><content:encoded><![CDATA[<p>The LifterLMS plugin for WordPress, in versions up to and including 10.2.1, contains an insecure deserialization vulnerability identified as CVE-2026-104723. The vulnerability exists within the lesson creation process, where the plugin improperly handles untrusted input during the metadata processing phase. To exploit this, an attacker must possess an account with at least 'edit_course' capabilities, such as an Instructor or LMS Manager.</p>
<p>While the LifterLMS codebase itself does not contain a Property-Oriented Programming (POP) chain, the vulnerability allows an attacker to inject arbitrary PHP objects that can be exploited if other plugins or themes installed on the same WordPress instance provide the necessary gadgets. Successful exploitation, in conjunction with a separate vulnerable component, may lead to arbitrary file deletion, unauthorized data retrieval, or remote code execution. This highlights the risk posed by the aggregate attack surface of complex CMS environments where multiple plugins interact.</p>
<h2 id="impact">Impact</h2>
<p>The impact of this vulnerability is contingent upon the presence of auxiliary POP chains within the WordPress environment. If a chain is present, an attacker could achieve full site compromise, execute remote code, or modify sensitive system files. The vulnerability specifically targets environments using LifterLMS for course management, exposing educational institutions and online training platforms to potential data breaches and service disruption.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade LifterLMS to a version beyond 10.2.1 immediately to resolve the underlying deserialization flaw.</li>
<li>Audit the WordPress environment for unused plugins or themes, as these may contain POP chains that could be leveraged by this vulnerability.</li>
<li>Apply the principle of least privilege by reviewing user roles and stripping 'edit_course' capabilities from any accounts that do not strictly require them for course administration.</li>
<li>Implement Web Application Firewall (WAF) rules to monitor for suspicious POST requests containing serialized PHP objects directed at lesson creation endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>