PatchSiren cyber security CVE debrief
CVE-2025-69359 WPFunnels CVE debrief
A Missing Authorization vulnerability in the Creator LMS plugin allows attackers to exploit incorrectly configured access control security levels. This issue affects Creator LMS versions from n/a through 1.1.12. The vulnerability can lead to unauthorized access and potential exploitation if not properly mitigated. Defenders should verify the configuration of access control security levels in Creator LMS and ensure that proper authorization checks are in place to prevent potential exploitation. This involves reviewing the plugin's configuration, ensuring that access control security levels are correctly set, and monitoring for potential exploitation attempts. Additionally, defenders
- Vendor
- WPFunnels
- Product
- Creator LMS
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-06
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-06
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for configuring and maintaining the Creator LMS plugin should be aware of this vulnerability and take steps to verify and mitigate potential risks.
Why it matters
Defenders should prioritize verifying the configuration of access control security levels in Creator LMS and ensuring that proper authorization checks are in place to prevent potential exploitation.
- Defenders need to verify the configuration of access control security levels in Creator LMS to prevent potential exploitation
- Proper authorization checks must be ensured to prevent attackers from exploiting incorrectly configured security levels
Technical summary
The Creator LMS plugin has a Missing Authorization vulnerability that allows attackers to exploit incorrectly configured access control security levels. This issue affects Creator LMS versions from n/a through 1.1.12. The vulnerability is caused by a lack of proper authorization checks, which can lead to unauthorized access and potential exploitation. To mitigate this vulnerability, defenders should verify the configuration of access control security levels in Creator LMS and ensure that proper authorization checks are in place. This can be done by reviewing the
Defensive priority
Defenders should prioritize verifying the configuration of access control security levels in Creator LMS and ensuring that proper authorization checks are in place.
Recommended defensive actions
- Verify the configuration of access control security levels in Creator LMS
- Ensure proper authorization checks are in place
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-69359 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-69359
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-69359 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-69359
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.