Impact
The vulnerability lies in a missing capability check in the get_items_permissions_check function of the Creator LMS plugin. This oversight allows an authenticated user with contributor‑level access or higher to modify any WordPress option stored by the plugin, resulting in privilege escalation that can compromise site integrity. This flaw is identified as CWE‑862, Missing Authorization.
Affected Systems
All releases of the Creator LMS plugin identified as getwpfunnels:Creator LMS – Online Courses and eLearning Plugin, up to and including version 1.1.12, are affected on WordPress installations that have contributors or higher users. Earlier versions that include the missing check or that are beyond 1.1.12 are not vulnerable.
Risk and Exploitability
The CVSS score of 8.8 categorizes this defect as High severity. The EPSS score of < 1% suggests that active exploitation in the wild is currently very low, and it is not listed in CISA’s KEV catalog. However, because the threat requires only authenticated contributor‑level access—which is commonly available on many public WordPress sites—a determined attacker could quickly modify settings once the plugin is installed.
OpenCVE Enrichment