PatchSiren

Creator LMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Creator LMS CVE published 2026-10-08

CVE-2026-62128

The CVE-2026-62128 vulnerability is a Missing Authorization issue in the Creator LMS plugin for WordPress, affecting versions up to 1.2.21. This vulnerability allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized access or modifications. The CVSS score for this vulnerability is 5.3, indicating a medium severity level. Defenders responsible f [truncated]