Incorrect Privilege Assignment in DesignThemes LMS Elementor Pro Plugin
CVE-2026-27983
9.8CRITICAL
What is CVE-2026-27983?
The LMS Elementor Pro plugin by DesignThemes contains a vulnerability that allows for unauthorized privilege escalation. This flaw enables attackers to gain higher-level permissions than intended, potentially compromising the entire application. The affected version is LMS Elementor Pro up to and including 1.0.4. Ensure your WordPress site is updated to mitigate any risks associated with this vulnerability.
Affected Version(s)
LMS Elementor Pro 0 <= 1.0.4