Executive brief
The DesignThemes LMS WordPress plugin contains an unauthenticated privilege escalation vulnerability that allows attackers to gain elevated access without valid credentials. This could enable unauthorized administrative actions, data manipulation, or complete site compromise.
Technical details
This vulnerability is an unauthenticated privilege escalation flaw in the DesignThemes LMS WordPress plugin. The attack requires no prior authentication, meaning any remote attacker can exploit it over the network to gain elevated privileges. The exact root cause and vulnerable component are not detailed in available sources, but the impact allows attackers to escalate their privileges without valid credentials. A patch is expected to be available through the canonical CVE-2025-13542.
Affected products
- DesignThemes LMS
Timeline
- 2026-09-02: advisory: CVE-2025-13398 marked as duplicate of CVE-2025-13542; users directed to reference the canonical CVE instead