The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
History

Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes designthemes Lms
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes designthemes Lms
Wordpress
Wordpress wordpress

Tue, 02 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
Title DesignThemes LMS <= 1.0.4 - Unauthenticated Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-12-02T19:27:16.108Z

Updated: 2025-12-02T19:36:45.547Z

Reserved: 2025-11-22T13:49:34.767Z

Link: CVE-2025-13542

cve-icon Vulnrichment

Updated: 2025-12-02T19:36:41.428Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-02T20:15:49.670

Modified: 2025-12-04T17:15:25.860

Link: CVE-2025-13542

cve-icon Redhat

No data.