
CM Video Lessons Manager – Simplify video lessons management for better education Security & Risk Analysis
wordpress.org/plugins/cm-video-lesson-managerCreate and display video lessons on your site by importing Vimeo videos. Organize content and track students with this efficient LMS plugin.
Is CM Video Lessons Manager – Simplify video lessons management for better education Safe to Use in 2026?
Generally Safe
Score 100/100CM Video Lessons Manager – Simplify video lessons management for better education has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cm-video-lesson-manager" v1.8.10 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and has a history of no recorded vulnerabilities, suggesting a generally well-maintained codebase. However, significant concerns arise from its attack surface. Three out of eight identified entry points, specifically AJAX handlers, lack authentication checks, presenting a direct pathway for unauthenticated attackers to interact with potentially sensitive functionalities. Furthermore, the presence of the "unserialize" function, identified as a dangerous function, warrants caution, as improper handling of serialized data can lead to remote code execution vulnerabilities. While the taint analysis did not reveal critical or high severity issues, the existence of flows with unsanitized paths is a red flag that requires further investigation to ensure no exploitable vulnerabilities exist within these flows.
The absence of any past CVEs is a strong positive indicator of the plugin's security history. This suggests that the developers have either been diligent in patching any discovered issues promptly or that the plugin has not been a significant target for vulnerability research. However, this historical absence does not negate the risks identified in the static analysis. The combination of unprotected AJAX endpoints and the use of "unserialize" introduces inherent risks that need to be addressed, regardless of past vulnerability records. In conclusion, while the plugin benefits from secure SQL practices and a clean vulnerability history, the unauthenticated AJAX endpoints and the use of "unserialize" represent clear security weaknesses that should be prioritized for remediation.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: unserialize
- Flows with unsanitized paths
- Low percentage of proper output escaping
CM Video Lessons Manager – Simplify video lessons management for better education Security Vulnerabilities
CM Video Lessons Manager – Simplify video lessons management for better education Release Timeline
CM Video Lessons Manager – Simplify video lessons management for better education Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
CM Video Lessons Manager – Simplify video lessons management for better education Attack Surface
AJAX Handlers 4
Shortcodes 4
WordPress Hooks 26
Maintenance & Trust
CM Video Lessons Manager – Simplify video lessons management for better education Maintenance & Trust
Maintenance Signals
Community Trust
CM Video Lessons Manager – Simplify video lessons management for better education Alternatives
Tutor LMS – eLearning and online course solution
tutor
A complete WordPress LMS plugin to create any eLearning website easily.
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am …
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
lifterlms
Complete e-learning platform to sell online courses, protect lessons, offer memberships, and quiz students. WP Learning Management System.
MasterStudy LMS WordPress Plugin – for Online Courses and Education
masterstudy-lms-learning-management-system
Learning Management System and eLearning plugin for WordPress. Create easily LMS WordPress website, add and sell Courses, Lessons, Quizzes online.
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education
learning-management-system
The complete WordPress LMS plugin for course creation & monetization. Create engaging courses, lessons, quizzes, assignments & certificates.
CM Video Lessons Manager – Simplify video lessons management for better education Developer Profile
19 plugins · 22K total installs
How We Detect CM Video Lessons Manager – Simplify video lessons management for better education
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-video-lesson-manager/css/backend.css/wp-content/plugins/cm-video-lesson-manager/css/frontend.css/wp-content/plugins/cm-video-lesson-manager/js/utils.js/wp-content/plugins/cm-video-lesson-manager/js/paybox.js/wp-content/plugins/cm-video-lesson-manager/js/playlist.js/wp-content/plugins/cm-video-lesson-manager/js/backend.js/wp-content/plugins/cm-video-lesson-manager/js/vimeo-browser.js/wp-content/plugins/cm-video-lesson-manager/js/vimeo-browser-modal.js/wp-content/plugins/cm-video-lesson-manager/js/utils.js/wp-content/plugins/cm-video-lesson-manager/js/paybox.js/wp-content/plugins/cm-video-lesson-manager/js/playlist.js/wp-content/plugins/cm-video-lesson-manager/js/backend.jscm-video-lesson-manager/css/backend.css?ver=cm-video-lesson-manager/css/frontend.css?ver=cm-video-lesson-manager/js/utils.js?ver=cm-video-lesson-manager/js/paybox.js?ver=cm-video-lesson-manager/js/playlist.js?ver=cm-video-lesson-manager/js/backend.js?ver=cm-video-lesson-manager/js/vimeo-browser.js?ver=cm-video-lesson-manager/js/vimeo-browser-modal.js?ver=HTML / DOM Fingerprints
cmvl-channel-headercmvl-playlistcmvl-video-itemcmvl-video-titlecmvl-video-descriptioncmvl-access-deniedcmvl-not-foundcmvl-vimeo-browser-modal+9 moreCMVL Custom CSSdata-channel-iddata-video-iddata-category-iddata-viewdata-layoutdata-ajax+1 morecmvl_utilscmvl_paybox_optionscmvl_playlist_optionscmvl_backend_optionscmvl_vimeo_browser_options