The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for unauthenticated attackers to change status to "Trash" for every published post, therefore limiting the availability of the website's content.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Mar 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for unauthenticated attackers to change status to "Trash" for every published post, therefore limiting the availability of the website's content. | |
Title | LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-19T04:21:05.815Z
Updated: 2025-03-19T14:03:46.870Z
Reserved: 2025-03-13T16:43:28.074Z
Link: CVE-2025-2290

Updated: 2025-03-19T14:03:39.001Z

Status : Received
Published: 2025-03-19T05:15:41.180
Modified: 2025-03-19T05:15:41.180
Link: CVE-2025-2290

No data.