CVE-2025-15347: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15347 is a missing authorization vulnerability in the Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress that allows authenticated attackers to escalate privileges by updating arbitrary WordPress options. The flaw exists in the get_items_permissions_check function and affects all plugin versions up to and including 1.1.12. It was published on January 20, 2026, with the fix introduced in version 1.1.13. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), assigned by Wordfence (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the get_items_permissions_check function in includes/Rest/V1/SettingsController.php fails to verify whether the requesting user has the appropriate capability before allowing modifications to WordPress options. Because no capability check is enforced, any authenticated user with contributor-level access or above can send crafted REST API requests to update arbitrary site options. The patch introduced in version 1.1.13 adds the missing authorization check to this function (Wordfence, Plugin Changeset).

Impact

Successful exploitation allows an authenticated attacker with as little as contributor-level access to modify critical WordPress site options without authorization, enabling privilege escalation to administrative access. An attacker could leverage this to create new administrator accounts, inject malicious code, alter site settings, or redirect users to malicious sites — effectively achieving full compromise of the WordPress installation. The vulnerability has high confidentiality, integrity, and availability impact, as administrative control over a WordPress site grants broad access to all hosted content and user data (Wordfence, Red Hat CVE).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The vulnerability requires authentication (contributor role or above), which somewhat limits the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.032%, indicating a low current probability of exploitation in the wild. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability has been detected by Qualys scanners (detection ID 530864) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Creator LMS plugin at version 1.1.12 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible readme.txt files.
  2. Obtain contributor access: Register or compromise an account with at least contributor-level privileges on the target WordPress site.
  3. Identify the vulnerable REST endpoint: Locate the REST API endpoint handled by SettingsController.php (e.g., /wp-json/creatorlms/v1/settings or similar) that invokes get_items_permissions_check.
  4. Send unauthorized option update request: Craft an authenticated REST API request (using the contributor's session cookie or application password) to the settings endpoint with a payload that modifies a critical WordPress option — for example, setting users_can_register to 1 and default_role to administrator.
  5. Escalate privileges: With user registration enabled and the default role set to administrator, register a new account to gain full administrative access to the WordPress site.
  6. Post-exploitation: Use administrative access to install malicious plugins, create backdoors, exfiltrate data, or further compromise the hosting environment (Wordfence, Plugin Changeset).

Indicators of compromise

  • Network: Unusual authenticated REST API requests to Creator LMS settings endpoints (e.g., /wp-json/creatorlms/v1/settings) from contributor-level accounts; unexpected POST/PUT requests to WordPress REST API from non-administrative users.
  • Logs: WordPress debug or access logs showing REST API calls to SettingsController endpoints by low-privileged users; sudden changes to wp_options table entries (e.g., users_can_register, default_role, siteurl, admin_email).
  • File System: Newly installed plugins or themes not authorized by administrators; unexpected PHP files in the uploads directory indicative of web shell deployment.
  • WordPress Admin: Unexpected new administrator accounts in the user list; changes to site settings such as open registration or altered default user roles; unfamiliar plugins activated without admin action.

Mitigation and workarounds

The vendor released version 1.1.13 of the Creator LMS plugin, which adds the missing capability check in get_items_permissions_check to remediate this vulnerability — site administrators should update immediately (Plugin Changeset). As interim workarounds, restrict contributor-level and above access to only fully trusted users, and consider temporarily deactivating the plugin if an immediate update is not feasible. Additionally, monitor the wp_options table for unauthorized changes and implement a Web Application Firewall (WAF) rule to block unauthorized REST API access to the plugin's settings endpoints (Wordfence).

Community reactions

Wordfence reported the vulnerability and published it to their threat intelligence platform on January 20, 2026, with the weekly WordPress vulnerability report covering the January 19–25, 2026 period also highlighting it (Wordfence Blog). The vulnerability was noted in CISA's weekly vulnerability bulletin for the week of January 19, 2026 (CISA Bulletin). Social media activity was limited, with brief mentions on Mastodon by TheHackerWire and RedPacketSecurity, reflecting routine coverage rather than significant community concern given the lack of active exploitation.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management