Back to overview

CVE-2025-14156

CRITICAL
9.8
CVSS 3.1
Description
The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is due to the plugin not properly validating the 'role' parameter when creating new users via the `/fox-lms/v1/payments/create-order` REST API endpoint. This makes it possible for unauthenticated attackers to create new user accounts with arbitrary roles, including administrator, leading to complete site compromise.

Metadata

CVE ID
CVE-2025-14156
State
PUBLISHED
Assigner
Wordfence
Reserved
2025-12-05 20:32 UTC
Published
2025-12-15 14:25 UTC
Last updated
2025-12-15 14:50 UTC
Primary CWE
CWE-20
CWE-20 Improper Input Validation
Vendor / Product
ays-pro / Fox LMS – WordPress LMS Plugin
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
ays-pro Fox LMS – WordPress LMS Plugin 1.0.4.7 ≤ 1.0.5.1
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20 Improper Input Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview