Executive brief
The LMS theme for WordPress, used for managing educational content and online courses, contains a security flaw that allows attackers to run malicious scripts in a user's browser. If a site administrator or visitor clicks a specially crafted link, an attacker could steal login sessions, redirect users to malicious websites, or deface the site. This vulnerability is particularly risky because it does not require the attacker to have an account on the site.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Designthemes LMS theme for WordPress (versions <= 9.7) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript into the context of a victim's browser session. Exploitation requires a victim to interact with a malicious link or crafted page (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized actions on behalf of a privileged user, or delivery of malicious payloads. As of the advisory date, no official patch has been released.
Affected products
- Designthemes LMS Theme <= 9.7
Timeline
- 2025-11-07: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
- 2026-06-30: advisory: Patchstack published advisory
- 2026-07-02: disclosed: CVE published to NVD dataset