CVE-2025-15347
Creator LMS – WordPress LMS Plugin for Coaches, Cohorts & Course Creators に報告された脆弱性
概要
The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options.
影響を受けるバージョン
- 0以上 〜 1.1.12以下
対処方法
Creator LMS – WordPress LMS Plugin for Coaches, Cohorts & Course Creators を 1.1.13 以降に更新してください。これで本脆弱性は解消します。
Creator LMS – WordPress LMS Plugin for Coaches, Cohorts & Course Creators の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する