CVE-2025-2290: LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the deleteaccessplan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for unauthenticated attackers to change status to "Trash" for every published post, therefore limiting the availability of the website's content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2290?
CVE-2025-2290 has a medium severity rating due to its potential for Unauthenticated Post Trashing.
How do I fix CVE-2025-2290?
To fix CVE-2025-2290, update the LifterLMS plugin to version 8.0.2 or later.
Which versions of LifterLMS are affected by CVE-2025-2290?
CVE-2025-2290 affects all versions of the LifterLMS plugin up to and including version 8.0.1.
What type of vulnerability is CVE-2025-2290?
CVE-2025-2290 is classified as an Unauthenticated Post Trashing vulnerability.
What impact does CVE-2025-2290 have on a website?
CVE-2025-2290 allows unauthorized users to delete access plans, which can compromise site content management.