PatchSiren

lifterlms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH lifterlms CVE published 2026-10-10

CVE-2026-104723

CVE-2026-104723 LifterLMS PHP Object Injection vulnerability allows authenticated attackers with custom-level access to inject PHP objects via deserialization of untrusted input during lesson creation. A POP chain must be present via another plugin or theme for exploitation to have impact. Defenders should assess exposure, prioritize remediation, and monitor activities to prevent potential code execution, [truncated]