- Description
- The Fox LMS ā WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is due to the plugin not properly validating the 'role' parameter when creating new users via the `/fox-lms/v1/payments/create-order` REST API endpoint. This makes it possible for unauthenticated attackers to create new user accounts with arbitrary roles, including administrator, leading to complete site compromise.
- Source
- security@wordfence.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-20
- Hype score
- Not currently trending
CRITICAL SECURITY ALERT: CVE-2025-14156 The Fox LMS plugin for #WordPress (v1.0.5.1 and below) is vulnerable to unauthenticated privilege escalation. https://t.co/QbO7zMG6eA Attackers can create Administrator accounts, leading to full site takeover. š„ CVSS Score: 9.8 htt
@MNovofastovsky
19 Dec 2025
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
š“ CVE-2025-14156 - Critical The Fox LMS ā WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is due to the plugin not properly valid... https://t.co/5AEyyqwJ5W https://t.co/7X3jbYEnfk
@TheHackerWire
15 Dec 2025
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-14156: CRITICAL] Critical security alert: Fox LMS, a WordPress plugin, up to version 1.0.5.1 is vulnerable to privilege escalation. Attackers can create admin accounts via the API endpoint. Update ...#cve,CVE-2025-14156,#cybersecurity https://t.co/l9u2ouk9mo https://t.c
@CveFindCom
15 Dec 2025
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes