CVE-2025-2290
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-2290 is a vulnerability affecting the LifterLMS plugin, used for eLearning and online courses on WordPress websites. This issue, present in all versions up to 8.0.1, allows unauthenticated attackers to manipulate published posts by exploiting a missing capability check on the delete_access_plan function and related AJAX calls. As a consequence, the attackers can change the status of these posts to "Trash," subsequently limiting the availability of the website content. This vulnerability could lead to significant disruptions, emphasizing the importance of prompt patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LifterLMS Plugin
Affected Vendors
- WordPress