
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15347 is a missing authorization vulnerability in the Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress that allows authenticated attackers to escalate privileges by updating arbitrary WordPress options. The flaw exists in the get_items_permissions_check function and affects all plugin versions up to and including 1.1.12. It was published on January 20, 2026, with the fix introduced in version 1.1.13. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), assigned by Wordfence (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization) — the get_items_permissions_check function in includes/Rest/V1/SettingsController.php fails to verify whether the requesting user has the appropriate capability before allowing modifications to WordPress options. Because no capability check is enforced, any authenticated user with contributor-level access or above can send crafted REST API requests to update arbitrary site options. The patch introduced in version 1.1.13 adds the missing authorization check to this function (Wordfence, Plugin Changeset).
Successful exploitation allows an authenticated attacker with as little as contributor-level access to modify critical WordPress site options without authorization, enabling privilege escalation to administrative access. An attacker could leverage this to create new administrator accounts, inject malicious code, alter site settings, or redirect users to malicious sites — effectively achieving full compromise of the WordPress installation. The vulnerability has high confidentiality, integrity, and availability impact, as administrative control over a WordPress site grants broad access to all hosted content and user data (Wordfence, Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The vulnerability requires authentication (contributor role or above), which somewhat limits the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.032%, indicating a low current probability of exploitation in the wild. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability has been detected by Qualys scanners (detection ID 530864) (Feedly).
readme.txt files.SettingsController.php (e.g., /wp-json/creatorlms/v1/settings or similar) that invokes get_items_permissions_check.users_can_register to 1 and default_role to administrator./wp-json/creatorlms/v1/settings) from contributor-level accounts; unexpected POST/PUT requests to WordPress REST API from non-administrative users.SettingsController endpoints by low-privileged users; sudden changes to wp_options table entries (e.g., users_can_register, default_role, siteurl, admin_email).The vendor released version 1.1.13 of the Creator LMS plugin, which adds the missing capability check in get_items_permissions_check to remediate this vulnerability — site administrators should update immediately (Plugin Changeset). As interim workarounds, restrict contributor-level and above access to only fully trusted users, and consider temporarily deactivating the plugin if an immediate update is not feasible. Additionally, monitor the wp_options table for unauthorized changes and implement a Web Application Firewall (WAF) rule to block unauthorized REST API access to the plugin's settings endpoints (Wordfence).
Wordfence reported the vulnerability and published it to their threat intelligence platform on January 20, 2026, with the weekly WordPress vulnerability report covering the January 19–25, 2026 period also highlighting it (Wordfence Blog). The vulnerability was noted in CISA's weekly vulnerability bulletin for the week of January 19, 2026 (CISA Bulletin). Social media activity was limited, with brief mentions on Mastodon by TheHackerWire and RedPacketSecurity, reflecting routine coverage rather than significant community concern given the lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."