Description
Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes LMS Addon: from n/a through <= 2.6.
Published: 2025-12-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from missing authorization checks within the DesignThemes LMS Addon plugin for WordPress. The plugin fails to enforce proper access control for certain administrative functions, allowing a user without sufficient privileges to gain full control over the plugin’s configuration and potentially other site resources. The weakness is identified as CWE-862, indicating broken access control. The consequence of exploitation is that an attacker could modify learning management settings, insert or delete content, or otherwise tamper with course data, thereby compromising data integrity, confidentiality, and availability for the affected site.

Affected Systems

The affected product is the DesignThemes LMS Addon WordPress plugin, version 2.6 and earlier. Any WordPress installation that has this plugin present and configured is vulnerable unless the plugin has been updated beyond the 2.6 release.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity, and the EPSS score of less than 1% indicates a very low yet non-zero likelihood of exploitation at the time of analysis. This entry is not listed in the CISA KEV catalog. The vulnerability can be exploited by any authenticated user who can invoke the plugin’s administrative endpoints, so the likely attack vector is via web interfaces with limited privilege. While no public exploits are documented, the lack of enforcement of authorization checks makes the risk tangible pending user authorization.

Generated by OpenCVE AI on April 29, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the DesignThemes LMS Addon to a version newer than 2.6 once available from the vendor
  • If an upgrade cannot be applied, disable or remove the plugin completely from the WordPress installation
  • Apply restrictive role‑based access controls to limit administrative actions within the plugin, ensuring that only trusted users have permission to modify LMS settings

Generated by OpenCVE AI on April 29, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes designthemes Lms
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes designthemes Lms
Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes LMS Addon: from n/a through <= 2.6.
Title WordPress DesignThemes LMS Addon plugin <= 2.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Designthemes Designthemes Lms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:33.411Z

Reserved: 2025-12-29T11:17:52.922Z

Link: CVE-2025-68982

cve-icon Vulnrichment

Updated: 2025-12-30T21:45:58.303Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T11:15:56.853

Modified: 2026-04-27T19:16:39.323

Link: CVE-2025-68982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:15:14Z

Weaknesses