External risk intelligence

Fox LMS WordPress Plugin Privilege Escalation via Unauthenticated User Creation

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-14156

The vulnerability exists in a WordPress LMS plugin within a REST API endpoint designed to handle order creation. Such endpoints on public-facing websites are commonly exposed to the internet to facilitate user interaction and commerce, making this attack surface frequently reachable in standard web deployments.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in a WordPress plugin that allows learning management systems to manage user roles. This flaw could enable unauthorized individuals to create new administrator accounts, potentially leading to a full compromise of the affected WordPress site. The primary concern is to determine if this specific plugin is in use within the organization's environment.

  • Attackers can create admin accounts easily.
  • Confirm if this WordPress plugin is used.
  • Assess business impact and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can leverage a flaw in the Fox LMS WordPress plugin to escalate their privileges. By interacting with a specific REST API endpoint, an attacker can create new user accounts without needing any existing access. This allows them to assign administrator privileges to these new accounts, granting them full control over the WordPress site.

  • Attackers need no prior authentication.
  • A specific REST API endpoint is used.
  • Complete site compromise is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to create new user accounts with elevated privileges, such as administrator access, on a WordPress site using the Fox LMS plugin. This could lead to the complete compromise of the website.

  • Website user data and administrative control at risk.
  • Unauthenticated users may create accounts via API.
  • Complete website compromise is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Fox LMS WordPress plugin's privilege escalation vulnerability likely impacts WordPress site administrators and the platform/infrastructure teams responsible for managing the WordPress environment. The initial focus should be on identifying all instances of the affected plugin, confirming their exposure to the internet, and assessing business criticality. Once these systems are identified and ownership is confirmed, a risk-based remediation plan can be developed, potentially involving coordination with the plugin vendor or implementing temporary mitigation strategies if immediate patching is not feasible.

  • Identify affected WordPress instances.
  • Verify public reachability and criticality.
  • Plan remediation with site owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Fox LMS WordPress plugin?

Fox LMS is a plugin designed for WordPress sites to create and manage a Learning Management System. It provides functionality for users to enroll in courses, track progress, and manage payment processing directly through the WordPress dashboard.

What is the vulnerability in CVE-2025-14156?

This vulnerability is classified as CWE-20, which relates to Improper Input Validation. In this case, the plugin fails to check the permissions or the legitimacy of a 'role' parameter when a user creates an order. Because the software accepts this input without verification, an attacker can designate themselves as an administrator during account creation, effectively bypassing the security controls that normally restrict who can hold high-level site privileges.

Does this flaw trigger if I am already logged in?

The vulnerability is triggered by interacting with a specific REST API endpoint designed for payment and order creation. It does not require any prior authentication, meaning an attacker does not need an existing account or to be logged in to initiate the request. Conversely, the bug is not triggered by standard site navigation or administrative tasks performed through the regular WordPress dashboard interface.

How do I know if my site is at risk?

According to Halo Surface Signal, this vulnerability is particularly relevant because it resides in a REST API endpoint often left accessible to the public to support online commerce. If your WordPress site uses the affected versions of the Fox LMS plugin and that specific API endpoint is reachable over the internet, your site is exposed. Systems that are not internet-facing or do not use this specific payment creation feature have a different risk profile.

How should I respond to this threat?

The first step is to inventory your WordPress environment to identify any instances running the Fox LMS plugin version 1.0.5.1 or earlier. Once identified, evaluate the criticality of those specific sites and determine if the plugin can be updated or if access to the vulnerable API endpoint can be restricted. Coordinate with your site administrators to verify the presence of the plugin and manage the transition to a patched state.

References