Back
CVE-2019-15896
CRITICAL
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.
Published: Sep 10, 2019
Modified: Jun 17, 2026
CWE-306
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| lifterlms | lifterlms | * |
GitHub Security Advisory GHSA-6c4r-hprj-699g
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import...
References (6)
- https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-lifterlms-plugin/ Exploit, Third Party Advisory
- https://wordpress.org/plugins/lifterlms/#developers Release Notes
- https://wpvulndb.com/vulnerabilities/9871 Third Party Advisory
- https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-lifterlms-plugin/ Exploit, Third Party Advisory
- https://wordpress.org/plugins/lifterlms/#developers Release Notes
- https://wpvulndb.com/vulnerabilities/9871 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
7.45%
Top 6% most likely to be exploited
Threat Score
41.4 / 100
Data Sources
NVD
EPSS
GitHub