What is CVE-2026-14231?
This vulnerability exists in the LifterLMS WordPress plugin versions before 10.0.10, where a select2 query AJAX handler lacks a capability check, only verifying user login. This allows any authenticated user with subscriber-level access to read titles of internal post types such as coupon codes. Immediate plugin update to the latest version is recommended.
Azərbaycanca: Bu boşluq LifterLMS WordPress plugin-in 10.0.10 versiyasından əvvəlki versiyalarında aşkarlanıb, burada select2 query AJAX handler-lərindən birində capability check aparılmır, yalnız istifadəçinin daxil olması yoxlanılır. Bu, subscriber səviyyəli hər hansı autentifikasiya olunmuş istifadəçiyə kupon kodları kimi daxili post tiplərinin başlıqlarını oxumağa imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What type of data can be accessed without authorization through CVE-2026-14231 in the LifterLMS plugin?
This vulnerability allows any authenticated user with subscriber-level access to read titles of internal post types such as coupon codes.
What is the root cause of CVE-2026-14231?
The vulnerability exists because one of the select2 query AJAX handlers lacks a capability check, only verifying user login.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.