CVE-2026-5207 | chrisbadgett LifterLMS Plugin up to 9.2.1 on WordPress edit_post order sql injection (EUVD-2026-21660)
A vulnerability marked as critical has been reported in chrisbadgett LifterLMS Plugin up to 9.2.1 on WordPress. Impacted is the function edit_post. Performing a manipulation of the argument order results in sql injection.
This vulnerability is known as CVE-2026-5207. Remote exploitation of the attack is possible. No exploit is available.