Access Control Configuration Flaw in WPFunnels Creator LMS by Patchstack
CVE-2025-69359
5.3MEDIUM
What is CVE-2025-69359?
The WPFunnels Creator LMS application is vulnerable to a missing authorization issue that allows attackers to exploit incorrectly configured access control security levels. This vulnerability impacts versions from n/a up to and including version 1.1.12, potentially enabling unauthorized access to restricted functionalities. Proper access control measures should be implemented to protect against unwanted access.
Affected Version(s)
Creator LMS 0 <= 1.1.12