WordPress security by component
DT LMS
DT LMS (dt-lms-lite) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
dt-lms-liteSafe-version coverage
0%
0 of 1 published CVE include confirmed safe-version guidance.
Last checked .
This measures remediation-data coverage in this archive. It is not a claim that the plugin is vulnerability-free or insecure.
Latest vulnerability
CVE-2026-11355: DT LMS exposes unauthenticated plugin option updates
DT LMS through 1.1 registers dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings on unauthenticated AJAX hooks without capability or nonce checks. Each passes request data directly to update_option(), letting an unauthenticated attacker overwrite Point-of-Contact email, skin, branding, and other LMS options for all visitors.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-11355
DT LMS exposes unauthenticated plugin option updates
DT LMS through 1.1 registers dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings on unauthenticated AJAX hooks without capability or nonce checks. Each passes request data directly to update_option(), letting an unauthenticated attacker overwrite Point-of-Contact email, skin, branding, and other LMS options for all visitors.
|
See mitigation notes |
CVE5.3
NVDPending
|