Impact
The current vulnerability permits an authenticated contributor to upload arbitrary files to the WordPress site through the Creator LMS plugin. This flaw stems from insecure handling of file types (CWE-434) and can allow an attacker to place executable code on the web server. If the uploaded file is executed, the attacker could compromise the full confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
The affected component is the WPFunnels Creator LMS plugin for WordPress, versions 1.2.21 and earlier. Affected users are those running the plugin without updating to at least 1.2.22. The vulnerability applies to all WordPress sites where the plugin is installed and the contributor role has access to the upload feature.
Risk and Exploitability
The CVSS score of 9.9 classifies this flaw as Critical. The EPSS score is not available, indicating no current exploitation probability data, and the vulnerability is not listed in CISA’s KEV catalogue. Nevertheless, because the flaw can be triggered via the web interface by an authenticated contributor, the attack vector is likely web-based. Successful exploitation would grant the attacker the same privileges as the contributing user, potentially leading to full site compromise.
OpenCVE Enrichment