CVE-2026-14231
MEDIUMLifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts
Title source: cnaDescription
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/2a353964-9f4c-4528-b187-42766f0cfaed/
Scores
CVSS v3
4.3
EPSS
0.0016
EPSS Percentile
5.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
None/LifterLMS
< 10.0.10
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026