CVE-2025-13542: DesignThemes LMS <= 1.0.4 - Unauthenticated Privilege Escalation
The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlmsregisteruserfrontend' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13542?
CVE-2025-13542 is classified as a Privilege Escalation vulnerability affecting the DesignThemes LMS plugin for WordPress.
How do I fix CVE-2025-13542?
To address CVE-2025-13542, upgrade the DesignThemes LMS plugin to version 1.0.5 or later where the vulnerability is patched.
What are the consequences of CVE-2025-13542?
Exploitation of CVE-2025-13542 allows unauthenticated users to register with higher user roles than intended, potentially compromising site security.
Which versions are affected by CVE-2025-13542?
CVE-2025-13542 affects all versions of the DesignThemes LMS plugin up to and including version 1.0.4.
Who is vulnerable to CVE-2025-13542?
Any WordPress site using the DesignThemes LMS plugin version 1.0.4 or earlier is vulnerable to CVE-2025-13542.