CVE 8.8 HIGH

Creator LMS – The LMS for Creators, Coaches, and Trainers <= 1.1.12 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update_CVE-2025-15347

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options.

AI Analysis

Missing capability check allows authenticated attackers to update arbitrary WordPress options, leading to privilege escalation.

Basic Information

ID CVE-2025-15347
Source Wordfence
Published Jan 20, 2026 at 14:26
Modified Jan 20, 2026 at 14:50

Affected Product

Vendor getwpfunnels
Product Creator LMS – The LMS for Creators, Coaches, and Trainers
Version *
Affected Versions getwpfunnels Creator LMS – The LMS for Creators, Coaches, and Trainers *

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor getwpfunnels
Product Creator LMS – The LMS for Creators, Coaches, and Trainers
Version 1.1.12 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.