CVE-2025-52799: WordPress LMS theme <= 9.2 - Reflected Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes LMS allows Reflected XSS. This issue affects LMS: from n/a through 9.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes LMS lms allows Reflected XSS.This issue affects LMS: from n/a through <= 9.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52799?
CVE-2025-52799 is classified as a medium severity vulnerability due to its Reflected XSS impact.
How do I fix CVE-2025-52799?
To fix CVE-2025-52799, update DesignThemes LMS to the latest version beyond 9.1 that addresses this vulnerability.
Which versions of DesignThemes LMS are affected by CVE-2025-52799?
CVE-2025-52799 affects DesignThemes LMS versions up to and including 9.1.
What types of attacks can exploit CVE-2025-52799?
CVE-2025-52799 enables attackers to perform Reflected XSS attacks, potentially compromising user sessions.
Is WordPress affected by CVE-2025-52799?
Yes, the WordPress LMS theme versions up to and including 9.1 are affected by CVE-2025-52799.