CVE-2026-62129
Received Received - Intake

Contributor Arbitrary File Upload in Creator LMS

Vulnerability report for CVE-2026-62129, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Patchstack

Description

Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
WPFunnels Creator LMS n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Arbitrary File Upload flaw in the WordPress Creator LMS Plugin versions 1.2.21 and below. It allows users with contributor or similar roles to upload malicious files to the server, potentially leading to a full system takeover.

Detection Guidance

Check for unauthorized file uploads in the Creator LMS plugin directory, particularly files with unexpected extensions or in unusual locations. Review server logs for POST requests to upload endpoints. Use tools like grep to search for suspicious file types or paths in the plugin's upload directories.

Impact Analysis

Attackers could exploit this to upload harmful files, gaining control of your website. This may result in data theft, malware distribution, or complete site compromise. The high CVSS score (9.9) indicates severe risk.

Mitigation Strategies

Update the Creator LMS plugin to version 1.2.22 or later immediately. If updating is not possible, apply mitigations such as vulnerability-specific rules or enable auto-updates. Restrict file upload permissions to trusted users only and monitor for unauthorized file changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62129. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart