Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-15896 — LifterLMS <= 3.34.5 - Unauthenticated Options Import | Kitploit
Tools/GitHubGitHub/randomrobbiebf/cve-2019-15896
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthentication
GitHubrandomrobbiebf/cve-2019-15896

CVE-2019-15896

LifterLMS <= 3.34.5 - Unauthenticated Options Import

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-15896

LifterLMS <= 3.34.5 - Unauthenticated Options Import

Description

Unauthenticated Options Import, which could lead to

  • Website Redirection

  • Administrator Account Creation

  • Content Injection

  • Stored XSS

The issues have been reported as fixed in 3.35.0. However v3.35.1 added additional input sanitisation and filtering.

How to use

$ python3 CVE-2019-15896.py --url http://wordpress.lan --username radmin --email [email protected] LifterLMS <= 3.34.5 - Unauthenticated Options Import Exploit By Ramdom Robbie Once ran check your email for the forgotten password link. Password reset email sent to [email protected]

root@kitploit:~

Info
---

Requires access to login.php and working email address and the site needs to be able to send emails

root@kitploit:~
Download Tool