VYPR
Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026

LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts

CVE-2026-14231

Description

The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.