CVE-2026-5207 - LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter
CVE ID :CVE-2026-5207
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' paramete...
Related Vulnerabilities
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-33457: Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allo MEDIUM
- CVE-2026-5217: The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin f HIGH
- CVE-2026-32930: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-36234: itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php v CRITICAL
Related Coverage
Threat Actors