Access Control Security Flaw in Creator LMS by Creator LMS
CVE-2026-62128
5.3MEDIUM
What is CVE-2026-62128?
The Creator LMS plugin has a missing authorization vulnerability that arises from incorrectly configured access control security levels. This flaw allows unauthorized users to exploit the system, potentially leading to unauthorized actions or access to restricted data. The issue affects all versions of Creator LMS leading up to 1.2.21, necessitating urgent remediation to safeguard sensitive information and ensure proper access controls are in place.
Affected Version(s)
Creator LMS 0 <= 1.2.21