Description
Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated reflected cross‑site scripting vulnerability exists in the DesignThemes LMS WordPress theme up to version 9.7. User‑controlled data is echoed back without proper encoding, enabling an attacker to inject JavaScript that will execute in the browser of anyone who views the affected page. This is an input validation weakness identified as CWE‑79.

Affected Systems

The vulnerability affects only the DesignThemes LMS WordPress theme, versions 9.7 and earlier; no other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests that exploitation attempts are unlikely, and the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, relying on a crafted request that triggers the theme to echo malicious browser, because the flaw is unauthenticated and reflected.

Generated by OpenCVE AI on July 21, 2026 at 12:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the LMS WordPress theme to the latest release that addresses the XSS is not immediately available, deactivate or remove the LMS theme to eliminate the vulnerable code.
  • Deploy a web‑application firewall or implement application‑layer filtering rules to reject requests containing script payloads aimed at LMS theme endpoints.
  • Configure a restrictive Content Security Policy to block inline scripts and mitigate potential XSS impact.

Generated by OpenCVE AI on July 21, 2026 at 12:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes lms
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes lms
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
Title WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Designthemes Lms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:51:33.339Z

Reserved: 2026-02-19T09:52:08.215Z

Link: CVE-2026-27404

cve-icon Vulnrichment

Updated: 2026-07-02T14:51:29.534Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')