plugin

Creatorlms Vulnerabilities

3 known security issues reported for the Creatorlms WordPress plugin. Most recent disclosed Mar 20, 2026.

2 high 1 medium

Running Creatorlms on your site? Check whether your installed version is affected.

Scan your site free

Creator LMS – Online Courses and eLearning Plugin <= 1.1.18 - Authenticated (Contributor+) Privilege Escalation

high

The Creator LMS – Online Courses and eLearning Plugin plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.18. This makes it possible for authenticated attackers, with Contributor-level access and above, to elevate their privileges to that of an administrator.

CVSS:
8.8
Affected:
up to 1.1.18
Fixed in:
1.1.19
Disclosed:
Mar 20, 2026

CVE-2026-32530 on NVD →

Creator LMS – The LMS for Creators, Coaches, and Trainers <= 1.1.12 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update

high

The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible f...

CVSS:
8.8
Affected:
up to 1.1.12
Fixed in:
1.1.13
Disclosed:
Jan 20, 2026

CVE-2025-15347 on NVD →

Creator LMS <= 1.1.12 - Missing Authorization

medium

The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.1.12
Fixed in:
1.1.13
Disclosed:
Jan 10, 2026

CVE-2025-69359 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database