Access violation vulnerability in LifterLMS – WordPress LMS Plugin for eLearning 7.4.2

The LifterLMS plugin for WordPress is vulnerable to a security issue known as Directory Traversal. This means that attackers who have access to administrator or LMS manager accounts may be able to read the contents of specific CSV files on the server, which can contain sensitive information. They may also be able to delete those files from the server. The vulnerability exists in versions of the plugin up to and including 7.4.2.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.