📦 Lifterlms

by Lifterlms

🔍 What is Lifterlms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-52717

CRITICAL CVSS 9.3 Jun 27, 2025

This SQL injection vulnerability in the LifterLMS WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all LifterLMS installations from unknown versions thro...

CVE-2024-4743

CRITICAL CVSS 9.8 Jun 5, 2024

This SQL injection vulnerability in the LifterLMS WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject malicious SQL queries through the 'orderBy' paramete...

CVE-2024-7349

HIGH CVSS 7.2 Sep 6, 2024

This vulnerability allows authenticated attackers with administrator-level access to perform blind SQL injection attacks via the 'order' parameter in the LifterLMS WordPress plugin. Attackers can extr...

CVE-2021-24562

HIGH CVSS 7.5 Aug 23, 2021

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the LifterLMS WordPress plugin. It allows authenticated students to access other students' answers and grades by manipula...

CVE-2024-13619

MEDIUM CVSS 6.1 May 15, 2025

This vulnerability in the LifterLMS WordPress plugin allows attackers to inject malicious scripts via unsanitized parameters, which are then reflected back in web pages. It primarily targets high-priv...

CVE-2025-2290

MEDIUM CVSS 5.3 Mar 19, 2025

The LifterLMS WordPress plugin has an unauthenticated post trashing vulnerability that allows attackers without credentials to move all published posts to the trash, making website content unavailable...