Executive brief
DT LMS is a WordPress plugin that provides learning management system functionality for websites. An attacker can modify critical plugin settings—including email addresses and branding—without authentication or permission, allowing them to redirect communications, impersonate administrators, or deface the learning platform for all users.
Technical details
The vulnerability is a missing capability check and nonce verification in multiple AJAX handlers (dtlms_save_poc_settings, dtlms_save_skin_settings, dtlms_save_options_settings) registered on wp_ajax_nopriv_* hooks. These handlers accept unauthenticated requests and pass user-supplied data directly to update_option() without sanitization or authorization checks. An attacker can send a crafted AJAX request to overwrite arbitrary plugin options in the wp_options table, including Point-of-Contact email and skin configuration. No authentication or user interaction is required; the vulnerability is network-accessible and trivial to exploit. Patches are available in versions after 1.1.
Affected products
- DT LMS DT LMS up to and including 1.1
Timeline
- 2026-09-12: disclosed