peter bassill · operator
$ cve CVE-2025-14156 JSON

CVE-2025-14156

9.8
CRITICAL · CVSS 3.1 · EPSS 6.8% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is due to the plugin not properly validating the 'role' parameter when creating new users via the `/fox-lms/v1/payments/create-order` REST API endpoint. This makes it possible for unauthenticated attackers to create new user accounts with arbitrary roles, including administrator, leading to complete site compromise.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.81% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2025-12-15
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD