CVE-2026-32530
8.8WPFunnels · Creator LMS
An incorrect privilege assignment vulnerability in the WPFunnels Creator LMS plugin allows authenticated attackers to perform privilege escalation.
Executive summary
A critical privilege escalation vulnerability in the WPFunnels Creator LMS plugin allows authenticated attackers to gain elevated access, posing a severe risk to system integrity.
Vulnerability
This vulnerability involves an Incorrect Privilege Assignment (CWE-266) within the Creator LMS plugin. It allows an attacker who already possesses low-level authenticated access to escalate their privileges, potentially gaining full administrative control over the affected installation.
Business impact
The ability for an authenticated user to escalate privileges poses a significant threat to the confidentiality, integrity, and availability of the entire WordPress instance. With a CVSS score of 8.8, this flaw is categorized as High severity and could lead to unauthorized data access, malicious plugin installation, or complete site compromise. Organizations relying on this plugin for educational or course management services face substantial operational and reputational risks if these accounts are hijacked.
Remediation
Immediate Action: Audit all user accounts for suspicious activity and restrict access to the Creator LMS plugin until an official update resolving this vulnerability is confirmed available by the vendor.
Proactive Monitoring: Review WordPress user role assignments and monitor access logs for unusual administrative actions performed by accounts that previously held standard user privileges.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting plugin-specific endpoints, though this is a temporary measure and not a substitute for patching.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the High severity of this privilege escalation flaw, administrators must prioritize identifying all instances of the Creator LMS plugin within their environment. Organizations should maintain a posture of least privilege and prepare to apply the vendor update immediately upon its release to secure the platform against potential exploitation.
More WPFunnels CVEs
Sources
Originally found and disclosed by daroo | Patchstack Bug Bounty Program, per the CVE Program record.