CVE-2025-69359: WordPress Creator LMS plugin <= 1.1.12 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69359?
CVE-2025-69359 is classified as a Missing Authorization vulnerability due to incorrectly configured access control security levels in WPFunnels Creator LMS.
How do I fix CVE-2025-69359?
To fix CVE-2025-69359, update WPFunnels Creator LMS to the latest version that has addressed the access control issues.
What versions of Creator LMS are affected by CVE-2025-69359?
CVE-2025-69359 affects WPFunnels Creator LMS versions up to and including 1.1.12.
What are the consequences of exploiting CVE-2025-69359?
Exploiting CVE-2025-69359 could allow attackers to gain unauthorized access due to the broken access control configuration.
Who is the vendor responsible for CVE-2025-69359?
The vendor responsible for addressing CVE-2025-69359 is WPFunnels, the developer of the Creator LMS platform.