SQL Injection Vulnerability in LifterLMS Plugin for WordPress
CVE-2026-5207
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 April 2026
What is CVE-2026-5207?
The LifterLMS plugin for WordPress is susceptible to SQL Injection attacks through the 'order' parameter. This vulnerability affects all versions up to and including 9.2.1. Due to improper handling of user-supplied input and inadequate preparation in SQL queries, authenticated attackers with Instructor-level access can manipulate existing queries to include their own SQL commands. As a result, they could extract sensitive data from the underlying database, posing a significant risk to the affected sites and their users.
Affected Version(s)
LifterLMS β WP LMS for eLearning, Online Courses, & Quizzes 0 <= 9.2.1