Vulnerabilities > Lifterlms > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-03-31 CVE-2020-6008 Unrestricted Upload of File with Dangerous Type vulnerability in Lifterlms
LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
network
low complexity
lifterlms CWE-434
critical
9.8
2019-09-10 CVE-2019-15896 Missing Authentication for Critical Function vulnerability in Lifterlms
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress.
network
low complexity
lifterlms CWE-306
critical
9.8