PatchSiren cyber security CVE debrief
CVE-2026-104723 lifterlms CVE debrief
CVE-2026-104723 LifterLMS PHP Object Injection vulnerability allows authenticated attackers with custom-level access to inject PHP objects via deserialization of untrusted input during lesson creation. A POP chain must be present via another plugin or theme for exploitation to have impact. Defenders should assess exposure, prioritize remediation, and monitor activities to prevent potential code execution, data breaches, or other impacts. This vulnerability affects LifterLMS versions up to and including 10.2.1.
- Vendor
- lifterlms
- Product
- LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders of WordPress installations using LifterLMS, especially those with custom-level access or above, should assess exposure and prioritize remediation. Instructors, Instructor's Assistants, LMS Managers, and Administrators are roles that may be affected.
Why it matters
CVE-2026-104723 LifterLMS PHP Object Injection vulnerability requires assessment and remediation to prevent potential code execution, data breaches, or other impacts. Defenders should verify exposure, monitor activities, and prioritize updates.
- Potential for code execution if a POP chain is present via another plugin or theme
- Possible data retrieval or arbitrary file deletion depending on the POP chain
- Requires verification of LifterLMS version and presence of POP chains in other plugins or themes
- Monitoring and logging of lesson creation and editing activities recommended
Technical summary
The LifterLMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 10.2.1. This occurs via deserialization of untrusted input during lesson creation when a temporary lesson ID triggers the custom metadata path. An attacker with custom-level access and above can inject a PHP Object, but a POP chain must be present via another plugin or theme for exploitation to have impact.
Defensive priority
Assess exposure, prioritize remediation
Recommended defensive actions
- Assess exposure: Verify if LifterLMS version 10.2.1 or earlier is installed and in use.
- Prioritize remediation: Update LifterLMS to a version beyond 10.2.1 if possible.
- Review user roles: Ensure that roles with custom-level access and above are properly configured and monitored.
- Monitor for suspicious activity: Keep an eye on lesson creation and editing activities, especially those involving temporary lesson IDs.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Official CVE Program record and NVD vulnerability detail provide information on the LifterLMS PHP Object Injection vulnerability. Source references include Wordfence and LifterLMS plugin code analysis. The vulnerability requires verification of LifterLMS version and presence of POP chains in other plugins or themes. Defenders should verify exposure, monitor activities, and prioritize updates. Limited source detail is available; explicit evidence limits and defensive verification tasks are recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104723 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104723
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104723 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104723
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
LifterLMS <= 10.2.1 - Authenticated (Custom+) PHP Object Injection via 'custom' Lesson Data
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104723.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/lifterlms/tags/10.2.1/includes/admin/class.llms.admin.builder.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3729229/lifterlms/trunk/includes/admin/class.llms.admin.builder.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.