Impact
The DesignThemes LMS plugin for WordPress allows any visitor to register a new account using the 'dtlms_register_user_front_end' function. Because this function does not limit the role that can be assigned at registration, an attacker can submit a request with the role value set to 'administrator' and receive an administrator account. Obtaining direct administrator access enables modification of site settings, content, and user data with full control.
Affected Systems
DesignThemes LMS plugin version 1.0.4 and all earlier releases on WordPress sites such as the eGrad Education theme from ThemeForest are affected.
Risk and Exploitability
The vulnerability carries a CVSS base score of 9.8, indicating critical severity, but the EPSS score of less than 1% suggests that exploitation likelihood is currently low. The absence of this issue from the CISA KEV catalog means no known public exploits are documented. Attackers would need only an unauthenticated web request to the registration endpoint, making the entry point trivial and universally reachable.
OpenCVE Enrichment