CVE-2026-14231: CWE-200 Information Exposure in LifterLMS
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.
AI Analysis
Technical Summary
CVE-2026-14231 is an information exposure vulnerability (CWE-200) in the LifterLMS WordPress plugin prior to version 10.0.10. The vulnerability arises because one of the select2 query AJAX handlers only verifies that the user is logged in but does not perform a capability check. Consequently, authenticated users with minimal privileges (subscriber-level) can access the titles of internal post types, including sensitive data like coupon codes, by supplying the post type parameter in the AJAX request.
Potential Impact
Authenticated users with subscriber-level access can read titles of internal post types that should be restricted, such as coupon codes. This exposure could lead to unauthorized disclosure of sensitive information within the WordPress environment. There is no indication of remote code execution or privilege escalation, but the information leak could aid further attacks or unauthorized use of coupon codes.
Mitigation Recommendations
No official patch or remediation guidance is currently provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider restricting subscriber-level access or disabling the affected AJAX handler if feasible.
CVE-2026-14231: CWE-200 Information Exposure in LifterLMS
Description
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.
CVSS v3.1
Score 4.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14231 is an information exposure vulnerability (CWE-200) in the LifterLMS WordPress plugin prior to version 10.0.10. The vulnerability arises because one of the select2 query AJAX handlers only verifies that the user is logged in but does not perform a capability check. Consequently, authenticated users with minimal privileges (subscriber-level) can access the titles of internal post types, including sensitive data like coupon codes, by supplying the post type parameter in the AJAX request.
Potential Impact
Authenticated users with subscriber-level access can read titles of internal post types that should be restricted, such as coupon codes. This exposure could lead to unauthorized disclosure of sensitive information within the WordPress environment. There is no indication of remote code execution or privilege escalation, but the information leak could aid further attacks or unauthorized use of coupon codes.
Mitigation Recommendations
No official patch or remediation guidance is currently provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider restricting subscriber-level access or disabling the affected AJAX handler if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-30T12:47:48.451Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6aee089c2644c7f8a7ef40
Added to database: 07/30/2026, 06:24:08 UTC
Last enriched: 07/30/2026, 06:54:21 UTC
Last updated: 07/31/2026, 00:19:58 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.