External risk intelligence

Creator LMS Arbitrary File Upload Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-62129

This vulnerability affects a WordPress plugin, which functions as a web-based application. Web applications and their associated plugins are commonly deployed to be internet-facing to serve users or site visitors, making them a standard part of an organization's public-facing web presence.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Creator LMS, a learning management system. This issue could allow unauthorized users with some access to upload malicious files, potentially leading to significant compromise of the affected system and its data. The primary concern is to determine if our organization utilizes this specific software and is therefore exposed.

  • File upload flaw in learning system software.
  • Critical risk if Creator LMS is in use.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low-privileged access to Creator LMS could upload a malicious file. This file could then be executed by the system, potentially leading to a complete compromise of the application.

  • Requires low-privileged access.
  • Upload a malicious file.
  • Leads to application compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated contributor to upload arbitrary files to the server. This could impact system integrity when supported by the advisory.

  • Server-side file system.
  • Arbitrary file upload.
  • Potential system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a WordPress plugin, classified as external, likely impacts organizations with a public-facing web presence. Responsibility for addressing this will typically fall to the team managing the web application and its plugins, which could be a dedicated web development team, an IT infrastructure team, or a platform operations team. The first practical step is to identify all instances of the affected plugin, confirm their reachability and criticality, and then assign ownership for remediation planning based on the assessed risk.

  • Application owners should own the issue.
  • Verify plugin exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Creator LMS?

Creator LMS is a learning management system designed as a WordPress plugin. It enables organizations to create, manage, and deliver educational content or training courses directly through their WordPress website interface.

What does CWE-434 mean for CVE-2026-62129?

CWE-434 refers to Unrestricted Upload of File with Dangerous Type. In the context of this CVE, it means the software does not sufficiently validate or restrict the types of files a user can upload, potentially allowing an attacker to submit executable code instead of expected files.

How can an attacker trigger this file upload vulnerability?

An attacker needs low-privileged access to the Creator LMS application to initiate the upload process. Simply visiting the public-facing site without a valid, authenticated user account is generally insufficient to trigger this specific file upload flaw.

Is my site at risk if I run Creator LMS?

Halo Surface Signal indicates that because Creator LMS is a WordPress plugin, it is often deployed in internet-facing web environments to serve users. If your instance is reachable from the public internet, it falls into the category of systems that are commonly targeted.

What should I do first to manage CVE-2026-62129?

Start by identifying every instance of the Creator LMS plugin running across your infrastructure. Once you have a complete inventory, verify the reachability of those instances and coordinate with the team responsible for your web application to prioritize this risk.

References