CVE-2026-32530 HIGH

CVE-2026-32530: WordPress Creator LMS plugin <= 1.1.18 - Privilege Escalation vulnerability

Vendor Wpfunnels
Product Creator LMS
Weakness CWE-266
Published March 25, 2026
Last update April 29, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <= 1.1.18.

Explanation of Vulnerability in Simple Terms

02Summary

WPFunnels Creator LMS versions up to 1.1.18 contain an improper privilege escalation vulnerability. An authenticated user with low privileges can read sensitive data, modify site content, or disrupt service availability. The vulnerability requires network access and valid login credentials but no additional user interaction. Site administrators should update immediately to a version newer than 1.1.18.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, or disrupt service availability with a low-privilege account.

Potential impact on your site

04Site Impact

Any logged-in user can access restricted data, alter site content, or cause downtime without admin approval.

Conditions required to exploit

05Prerequisites

Valid login credentials with low-level user privileges; network access to the site.

Key dates

06Disclosure timeline

March 25, 2026 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE