PT-2025-51229 · WordPress · Fox Lms

Kenneth Dunn

·

Published

2025-12-15

·

Updated

2025-12-20

·

CVE-2025-14156

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fox LMS – WordPress LMS Plugin versions prior to 1.0.5.1
Description The Fox LMS – WordPress LMS Plugin does not properly validate the role parameter when creating new users via the /fox-lms/v1/payments/create-order API endpoint. This allows unauthenticated attackers to create new user accounts with arbitrary roles, including administrator, potentially leading to complete site compromise.
Recommendations Versions prior to 1.0.5.1 should be updated to version 1.0.5.1 or later.

Fix

LPE

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-14156

Affected Products

Fox Lms