CVE-2025-2290

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 19, 2025
CWE ID 862

Summary

CVE-2025-2290 is a vulnerability affecting the LifterLMS plugin, used for eLearning and online courses on WordPress websites. This issue, present in all versions up to 8.0.1, allows unauthenticated attackers to manipulate published posts by exploiting a missing capability check on the delete_access_plan function and related AJAX calls. As a consequence, the attackers can change the status of these posts to "Trash," subsequently limiting the availability of the website content. This vulnerability could lead to significant disruptions, emphasizing the importance of prompt patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • LifterLMS Plugin

Affected Vendors

  • WordPress