Path Traversal Vulnerability in Creator LMS by Patchstack
CVE-2026-97244
7.5HIGH
What is CVE-2026-97244?
A path traversal vulnerability exists in the Creator LMS plugin for WordPress that affects versions up to 1.2.19. This flaw can allow unauthorized users to gain access to sensitive files on the server by manipulating file paths. Malicious actors could exploit this vulnerability to read sensitive data or execute arbitrary code, posing significant security risks to affected installations.
Affected Version(s)
Creator LMS <= 1.2.19