CVE-2026-5207 - LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter
CVE ID :CVE-2026-5207
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' paramete...
Related Vulnerabilities
- CVE-2026-33618: Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController HIGH
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-36234: itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php v CRITICAL
- CVE-2026-22560: An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected MEDIUM
- CVE-2026-5226: The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
Related Coverage
Threat Actors