CVE-2026-97244: WordPress Creator LMS plugin <= 1.2.19 - Path Traversal vulnerability
Published Sep 30, 2026
·Updated
Contributor Path Traversal in Creator LMS <= 1.2.19 versions.
Affected Software
1 affected component
WordPress Creator LMS<=1.2.19
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Creator LMS pluginto a version that resolves this vulnerability.Fixed in 1.2.20
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker needs Contributor-level privileges in WordPress. The attack can be performed remotely and does not require user interaction.
2
What impact could successful exploitation have?
Successful exploitation may compromise confidentiality, integrity, and availability, all rated High in the supplied severity vector.
3
Which installations are affected?
WordPress sites using the Creator LMS plugin version 1.2.19 or earlier are affected according to the provided data.