CVE-2025-15347: Creator LMS – The LMS for Creators, Coaches, and Trainers <= 1.1.12 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update
The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the getitemspermissionscheck function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15347?
CVE-2025-15347 has a moderate severity level due to its potential for unauthorized data modification.
How do I fix CVE-2025-15347?
To fix CVE-2025-15347, update the Creator LMS plugin for WordPress to version 1.1.13 or later.
Who is affected by CVE-2025-15347?
Users of Creator LMS for WordPress versions 1.1.12 and earlier are affected by CVE-2025-15347.
What type of vulnerability is CVE-2025-15347?
CVE-2025-15347 is a missing authorization vulnerability that allows unauthorized users to modify settings.
What could be the impact of CVE-2025-15347?
The impact of CVE-2025-15347 includes potential arbitrary options updates, leading to unauthorized changes in the LMS.