What is CVE-2026-14207?
CVE-2026-14207 is a vulnerability in the LifterLMS WordPress plugin prior to version 10.0.10. It allows users with a course-editing role to inject JavaScript via the course pricing field, which then executes in an administrator's session when they view the course. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-14207, LifterLMS WordPress plaginində 10.0.10 versiyasından əvvəlki versiyalarda mövcud olan zəiflikdir. Kurs redaktə etmə səlahiyyəti olan istifadəçilər kurs qiymət sahəsinə JavaScript kodu yerləşdirə bilər və bu kod kursa baxan administratorun sessiyasında icra olunar. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What privileges are required to exploit CVE-2026-14207?
To exploit the vulnerability, a user must have course-editing permissions in the LifterLMS plugin.
How can I protect against CVE-2026-14207?
You should update the LifterLMS plugin to version 10.0.10 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.