Medium 6.5
2026-04-11< 9.2.2
LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter
Minimum safe version
9.2.2
Update to 9.2.2 or later to address 18 fixable vulnerabilities
LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter
CVE-2025-11923
LifterLMS <= 8.0.6 - Unauthenticated SQL Injection
CVE-2024-13619
LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing
CVE-2024-12596
CVE-2024-7349
CVE-2024-4743
CVE-2024-31363
CVE-2024-0377
CVE-2023-6160
LifterLMS < 4.21.1 - Reflected Cross-Site Scripting (XSS) via Coupon Code in Checkout
LMS by LifterLMS <= 4.21.0 - Reflected Cross-Site Scripting
WordPress LifterLMS plugin <= 4.21.0 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2019-15896
CVE-2020-6008
CVE-2021-24308
CVE-2021-24562