CVE-2026-62083 PUBLISHED

WordPress Creator LMS plugin <= 1.2.19 - Other vulnerability Type vulnerability

Assigner: Patchstack
Reserved: 13.07.2026 Published: 30.09.2026 Updated: 30.09.2026

Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor WPFunnels
Product Creator LMS
Versions Default: unaffected
  • affected from n/a to 1.2.19 (incl.)

Solutions

Update the WordPress Creator LMS plugin to the latest available version (at least 1.2.20).

Credits

  • khado | Patchstack Bug Bounty Program finder

References

Problem Types

  • CWE-1284 Improper Validation of Specified Quantity in Input CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs