The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course.
We have discovered 945 live websites that are affected by CVE-2026-14207.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 945 live websites (52% of Lifterlms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 11 versions ( 17% of all versions) |
| 464 websites | |
| 79 websites | |
| 57 websites | |
| 40 websites | |
| 30 websites | |
| 28 websites | |
| 26 websites | |
| 23 websites | |
| 23 websites | |
| 15 websites |
| .com | 508 websites |
| .org | 96 websites |
| .de | 39 websites |
| .fi | 32 websites |
| .net | 24 websites |
| .co.uk | 24 websites |
| .nl | 18 websites |
| .ca | 14 websites |
| .com.au | 14 websites |
| .be | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | **,*** | ||
| ***.org | ***,*** | ||
| ********************.org | ***,*** | ||
| *******.com | ***,*** | ||
| ********.com | ***,*** | ||
| *****************.nl | ***,*** | ||
| **************.com | ***,*** | ||
| **************.com | ***,*** | ||
| ******************.com | ***,*** | ||
| ****.org | ***,*** |
FAQ