Sceawere
Vulnerability Detail
CVE-2026-104723UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LifterLMS PHP Object Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 2h ago
- Vendor
- lifterlms
- Product
- LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via deserialization of untrusted input . This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. This vulnerability is only exploitable during lesson creation when a temporary lesson ID triggers the custom metadata path, and requires the attacker to hold a role with the edit_course capability, such as Instructor, Instructor's Assistant, LMS Manager, or Administrator.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-10T06:16:38.760Z",
"pubdate": "2026-10-10T06:16:38.760Z",
"executiveSummary": "The LifterLMS plugin for WordPress, in versions up to and including 10.2.1, contains a PHP Object Injection vulnerability arising from insecure deserialization of untrusted input.\nThis vulnerability resides within the plugin's metadata handling processes during lesson creation. While the plugin itself does not contain a Property-Oriented Programming (POP) chain, the presence of such chains in other installed themes or plugins can be leveraged to achieve critical impact.\nSuccessful exploitation requires the attacker to possess at least the 'edit_course' capability, typically associated with roles such as Instructor, Instructor's Assistant, LMS Manager, or Administrator.\nThe risk implication is significant if the target environment contains compatible POP chains, potentially allowing unauthorized file deletion, sensitive data exfiltration, or remote code execution (RCE).\nSecurity teams should prioritize updating LifterLMS to a patched version once available and conduct an audit of installed components for potential POP chain gadgets.",
"technicalDetails": "The vulnerability is rooted in the insecure deserialization of user-supplied input during the handling of temporary lesson IDs within the LifterLMS metadata path. When an authenticated user with sufficient privileges triggers the lesson creation process, the application processes metadata that is susceptible to PHP object injection.\nPHP Object Injection occurs when untrusted data is passed to the unserialize() function without adequate validation. In this context, an attacker can supply a serialized PHP object payload, which is then instantiated within the application's memory space.\nThe exploit flow is as follows: First, the attacker must authenticate with a role granted the 'edit_course' capability. Second, the attacker initiates a lesson creation sequence, specifically targeting the vulnerable code path that processes custom metadata associated with a temporary lesson ID. By injecting a crafted serialized object into this input vector, the attacker forces the application to deserialize the malicious input.\nAlthough the LifterLMS codebase does not contain inherent POP chains (class structures that can be chained together to perform unintended actions upon object destruction or method invocation), the vulnerability relies on the broader WordPress environment. If the target system hosts other plugins or themes containing 'gadget' classes—specifically those that implement magic methods such as __destruct(), __wakeup(), or __toString()—the attacker can leverage these to execute arbitrary code or manipulate file systems.\nUpon successful deserialization, if a gadget chain is identified, the post-exploitation impact depends entirely on the capabilities of the available gadgets. This could lead to local file inclusion (LFI), arbitrary file deletion via the destruction of file-handling objects, or arbitrary method invocation leading to RCE. The requirement for the 'edit_course' privilege significantly narrows the threat vector to authenticated insiders or compromised accounts, but the potential for lateral movement or privilege escalation within the CMS environment remains high if gadget chains are present."
}