CVE-2025-68982: WordPress DesignThemes LMS Addon plugin <= 2.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes LMS Addon: from n/a through <= 2.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68982?
CVE-2025-68982 has a high severity due to its potential for unauthorized access from incorrectly configured access control security levels.
How do I fix CVE-2025-68982?
To fix CVE-2025-68982, update DesignThemes LMS Addon to a version higher than 2.6 that addresses the missing authorization vulnerability.
What is the impact of CVE-2025-68982?
CVE-2025-68982 can allow attackers to exploit incorrect access controls, leading to unauthorized actions within the DesignThemes LMS Addon.
Which versions are affected by CVE-2025-68982?
CVE-2025-68982 affects DesignThemes LMS Addon versions from n/a up to and including version 2.6.
Is CVE-2025-68982 specific to WordPress?
Yes, CVE-2025-68982 specifically affects the DesignThemes LMS Addon used within WordPress installations.