Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-11355— DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions

Quick assessment

Affected
designthemes DT LMS – elearning, WordPress LMS Plugin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DT LMS – elearning(WordPress LMS 插件)在版本 1.1 及更早版本中存在数据可被未授权修改的漏洞。该漏洞源于多个 AJAX 处理函数(包括 、 和 )中缺少权限(capability)检查。这些处理函数注册在 钩子上,既没有进行权限检查,也没有进行 nonce 验证,且将用户提交的数据直接传递给 函数。这使得未认证的 attacker 能够覆盖 表中存储的任意插件选项值,包括联系人(Point-of-Contact)邮箱配置和皮肤/品牌设置,从而改变所有站点访客看到的 LMS 界面外

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-11355

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions
Source: CVE Program / CVE List V5
Vulnerability Description
The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings) in versions up to, and including, 1.1. These handlers are registered on the wp_ajax_nopriv_* hook and contain no capability check, no nonce verification, and pass user-supplied data directly to update_option(). This makes it possible for unauthenticated attackers to overwrite arbitrary plugin option values stored in the wp_options table, including Point-of-Contact email configuration and skin/branding settings, which can be used to alter the appearance and behavior of the LMS for all site visitors.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
designthemes DT LMS – elearning, WordPress LMS Plugin 0 ~ 1.1 -

II. Public POCs for CVE-2026-11355

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-11355

登录查看更多情报信息。

Security Blog Posts for CVE-2026-11355 (1)

Vendor Pages for CVE-2026-11355 (2)

Other References for CVE-2026-11355 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-11355

No comments yet


Leave a comment