CVE-2025-52833: WordPress LMS theme <= 9.2 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS allows SQL Injection. This issue affects LMS: from n/a through 9.1.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS lms allows SQL Injection.This issue affects LMS: from n/a through <= 9.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52833?
CVE-2025-52833 has a critical severity rating due to its potential to allow SQL Injection attacks.
How do I fix CVE-2025-52833?
To fix CVE-2025-52833, update DesignThemes LMS to version 9.1 or higher to mitigate the SQL Injection vulnerability.
What software is affected by CVE-2025-52833?
CVE-2025-52833 affects DesignThemes LMS and WordPress LMS versions up to and including 9.1.
What is the impact of CVE-2025-52833 on affected systems?
The impact of CVE-2025-52833 allows attackers to execute arbitrary SQL commands, potentially compromising data integrity and confidentiality.
Are there any known exploits for CVE-2025-52833?
As of now, there are no public reports of active exploits targeting CVE-2025-52833, but its critical nature makes it important to apply the fix immediately.