Path Traversal Vulnerability in Creator LMS by Patchstack
CVE-2026-97244

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-97244?

A path traversal vulnerability exists in the Creator LMS plugin for WordPress that affects versions up to 1.2.19. This flaw can allow unauthorized users to gain access to sensitive files on the server by manipulating file paths. Malicious actors could exploit this vulnerability to read sensitive data or execute arbitrary code, posing significant security risks to affected installations.

Affected Version(s)

Creator LMS <= 1.2.19

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JunHee CHO | Patchstack Bug Bounty Program
.