LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing
Vulnerability Description
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for unauthenticated attackers to change status to "Trash" for every published post, therefore limiting the availability of the website's content.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2290
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Michael Mazzolini
References
More from chrisbadgett
View All →Affected Vendor
chrisbadgett
View all reports →