VYPR

Creatorlms

by WordPress

CVEs (2)

  • CVE-2025-15347HigJan 20, 2026
    risk 0.57cvss 8.8epss 0.00

    The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options.

  • CVE-2025-69359MedJan 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.