CVE-2026-14207

LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information

The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course.


We have discovered 945 live websites that are affected by CVE-2026-14207.

Run a Free Instant Scan




Affected Software

Product  Lifterlms
Category Wordpress Plugins
Vulnerable Domains945 live websites (52% of Lifterlms install base)
Vulnerable Versions
  • from 9.2.3 through 10.0.10
Vulnerable Versions Count11 versions ( 17% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Mustafa Ahmed (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14207
United States464 websites



Germany79 websites
GB57 websites
Finland40 websites
Canada30 websites
France28 websites
Netherlands26 websites
Australia23 websites
Cyprus23 websites
Spain15 websites

Website Distribution by TLD

Number of websites using CVE-2026-14207
.com508 websites
.org96 websites
.de39 websites
.fi32 websites
.net24 websites
.co.uk24 websites
.nl18 websites
.ca14 websites
.com.au14 websites
.be9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14207

Top websites that are affected by CVE-2026-14207. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States**,***
***.org United States***,***
********************.org GB***,***
*******.com GB***,***
********.com United States***,***
*****************.nl Netherlands***,***
**************.com United States***,***
**************.com GB***,***
******************.com United States***,***
****.org United States***,***
See full domain list

FAQ

CVE-2026-14207 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Lifterlms
A total of 945 websites have been identified as vulnerable to CVE-2026-14207, based on global website indexing conducted by WebTechSurvey.
The Lifterlms is affected by the CVE-2026-14207 vulnerability.
Lifterlms versions up to 10.0.10 are vulnerable to CVE-2026-14207.
CVE-2026-14207 is resolved in version 10.0.10 of Lifterlms.