PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104723 lifterlms CVE debrief

CVE-2026-104723 LifterLMS PHP Object Injection vulnerability allows authenticated attackers with custom-level access to inject PHP objects via deserialization of untrusted input during lesson creation. A POP chain must be present via another plugin or theme for exploitation to have impact. Defenders should assess exposure, prioritize remediation, and monitor activities to prevent potential code execution, data breaches, or other impacts. This vulnerability affects LifterLMS versions up to and including 10.2.1.

Vendor
lifterlms
Product
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders of WordPress installations using LifterLMS, especially those with custom-level access or above, should assess exposure and prioritize remediation. Instructors, Instructor's Assistants, LMS Managers, and Administrators are roles that may be affected.

Why it matters

CVE-2026-104723 LifterLMS PHP Object Injection vulnerability requires assessment and remediation to prevent potential code execution, data breaches, or other impacts. Defenders should verify exposure, monitor activities, and prioritize updates.

  • Potential for code execution if a POP chain is present via another plugin or theme
  • Possible data retrieval or arbitrary file deletion depending on the POP chain
  • Requires verification of LifterLMS version and presence of POP chains in other plugins or themes
  • Monitoring and logging of lesson creation and editing activities recommended

Technical summary

The LifterLMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 10.2.1. This occurs via deserialization of untrusted input during lesson creation when a temporary lesson ID triggers the custom metadata path. An attacker with custom-level access and above can inject a PHP Object, but a POP chain must be present via another plugin or theme for exploitation to have impact.

Defensive priority

Assess exposure, prioritize remediation

Recommended defensive actions

  • Assess exposure: Verify if LifterLMS version 10.2.1 or earlier is installed and in use.
  • Prioritize remediation: Update LifterLMS to a version beyond 10.2.1 if possible.
  • Review user roles: Ensure that roles with custom-level access and above are properly configured and monitored.
  • Monitor for suspicious activity: Keep an eye on lesson creation and editing activities, especially those involving temporary lesson IDs.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

Official CVE Program record and NVD vulnerability detail provide information on the LifterLMS PHP Object Injection vulnerability. Source references include Wordfence and LifterLMS plugin code analysis. The vulnerability requires verification of LifterLMS version and presence of POP chains in other plugins or themes. Defenders should verify exposure, monitor activities, and prioritize updates. Limited source detail is available; explicit evidence limits and defensive verification tasks are recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104723 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104723

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104723 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104723

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.