CVE-2026-62083: WordPress Creator LMS plugin <= 1.2.19 - Other vulnerability Type vulnerability
Published Sep 30, 2026
·Updated
Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.
Affected Software
1 affected component
WordPress Creator LMS<=1.2.19
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Creator LMS pluginto a version that resolves this vulnerability.Fixed in 1.2.20
Event History
Sep 30, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is associated with Subscriber-level access, so an attacker would need a WordPress account with Subscriber privileges.
2
Can it be exploited remotely without user interaction?
Yes. The supplied vector indicates network access, low attack complexity, and no user interaction are required; however, the attacker must have low-level privileges.
3
What is the potential impact?
The vulnerability is rated medium severity with a 5.4 CVSS score. It may result in limited confidentiality and integrity impact, with no reported availability impact.
4
Which versions are affected?
Creator LMS versions through 1.2.19 are identified as affected.