Impact
The DT LMS – elearning plugin allows unauthenticated users to send AJAX requests that are handled by functions that omit capability checks, nonce verification, and pass user‑supplied data directly to update_option(). This flaw lets an attacker overwrite any plugin setting stored in the wp_options table, such as contact emails, branding images, or skin choices. The attacker can therefore alter the appearance and communication behavior of the LMS for all visitors without logging in or possessing any sites that have the DT LMS – elearning or WordPress LMS Plugin installed with a version equal to or lower than 1.1 are affected. No versions newer than 1.1 are known to be vulnerable; the plugin maintainers checks.
Affected Systems
The vendor is DesignThemes and the product is the DT LMS – elearning WordPress LMS Plugin. Versions up to and including 1.1 are vulnerable. WordPress sites that have this plugin installed at those versions are affected. No newer plugin versions are reported to be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range, while the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector is unauthenticated and requires no user privilege, an attacker only needs to send crafted HTTP requests to the vulnerable AJAX endpoints to experience for all site visitors.
OpenCVE Enrichment