Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14231 | 2 Lifterlms, Wordpress | 2 Lifterlms, Wordpress | 2026-07-30 | 4.3 Medium |
| The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type. | ||||
| CVE-2026-14207 | 2 Lifterlms, Wordpress | 2 Lifterlms, Wordpress | 2026-07-30 | 6.1 Medium |
| The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course. | ||||
Page 1 of 1.