peter bassill · operator
$ cve CVE-2019-15896 JSON

CVE-2019-15896

9.8
CRITICAL · CVSS 3.1 · EPSS 6.5% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.49% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2019-09-10
Last modified2026-06-17

Affected (1)

VendorProduct
lifterlmslifterlms

References

→ the Explorer  ·  watch your stack  ·  NVD