HIGH
lifterlms
CVE published 2026-10-10
CVE-2026-104723
CVE-2026-104723 LifterLMS PHP Object Injection vulnerability allows authenticated attackers with custom-level access to inject PHP objects via deserialization of untrusted input during lesson creation. A POP chain must be present via another plugin or theme for exploitation to have impact. Defenders should assess exposure, prioritize remediation, and monitor activities to prevent potential code execution, [truncated]