theme

Wplms Vulnerabilities

24 known security issues reported for the Wplms WordPress theme. Most recent disclosed Sep 22, 2025.

3 critical 10 high 5 medium

Running Wplms on your site? Check whether your installed version is affected.

Scan your site free

WPLMS <= 4.970 - Missing Authorization

medium

The WPLMS theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.970. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
5.4
Affected:
up to 4.970
Fixed in:
4.971
Disclosed:
Sep 22, 2025

CVE-2025-58668 on NVD →

WPLMS Learning Management System for WordPress [wplms] < 1.9

unknown

[en] The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

Affected:
up to 1.9
Fixed in:
1.9
Disclosed:
Jul 19, 2025

CVE-2015-10139 on NVD →

WPLMS <= 1.9.9 - Unauthenticated Arbitrary File Upload

critical

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server whic...

CVSS:
9.8
Affected:
up to 1.9.9
Fixed in:
1.9.9.1
Disclosed:
Dec 17, 2024

CVE-2024-56046 on NVD →

WPLMS <= 1.9.9 - Unauthenticated Privilege Escalation

critical

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to gain elevated access to a site.

CVSS:
9.8
Affected:
up to 1.9.9
Fixed in:
1.9.9.1
Disclosed:
Dec 17, 2024

CVE-2024-56043 on NVD →

WPLMS < 1.9.9.5.2 - Authenticated (Student+) Arbitrary File Upload

high

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with student-level access and above, to upload arbitrary files on the affected site's server which may make remote c...

CVSS:
8.8
Affected:
up to 1.9.9.5.2
Fixed in:
1.9.9.5.2
Disclosed:
Dec 17, 2024

CVE-2024-56052 on NVD →

WPLMS < 1.9.9.5 - Authenticated (Student+) Remote Code Execution

high

The WPLMS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.9.9.5 (exclusive). This makes it possible for authenticated attackers, with student-level access and above, to execute code on the server.

CVSS:
8.8
Affected:
up to 1.9.9.5
Fixed in:
1.9.9.5
Disclosed:
Dec 17, 2024

CVE-2024-56051 on NVD →

WPLMS < 1.9.9.5.3 - Authenticated (Subscriber+) Arbitrary File Upload

high

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.3 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remot...

CVSS:
8.8
Affected:
up to 1.9.9.5.3
Fixed in:
1.9.9.5.3
Disclosed:
Dec 17, 2024

CVE-2024-56050 on NVD →

WPLMS <= 1.9.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

high

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in all versions up to, and including, 1.9.9. This makes it possible for authenticated attackers, with Subscribe...

CVSS:
8.8
Affected:
up to 1.9.9
Fixed in:
1.9.9.1
Disclosed:
Dec 17, 2024

CVE-2024-56048 on NVD →

WPLMS < 1.9.9.5.2 - Authenticated (Instructor+) Arbitrary File Upload

high

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with instructor-level access and above, to upload arbitrary files on the affected site's server which may make remot...

CVSS:
8.8
Affected:
up to 1.9.9.5.2
Fixed in:
1.9.9.5.2
Disclosed:
Dec 17, 2024

CVE-2024-56054 on NVD →

WPLMS < 1.9.9.5.2 - Authenticated (Contributor+) Arbitrary File Upload

high

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remo...

CVSS:
8.8
Affected:
up to 1.9.9.5.2
Fixed in:
1.9.9.5.2
Disclosed:
Dec 17, 2024

CVE-2024-56057 on NVD →

WPLMS < 1.9.9.5 - Unauthenticated Arbitrary Directory Deletion

high

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in all versions up to 1.9.9.5 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary directories on the server.

CVSS:
8.2
Affected:
up to 1.9.9.5
Fixed in:
1.9.9.5
Disclosed:
Dec 17, 2024

CVE-2024-56045 on NVD →

WPLMS < 1.9.9.5.2 - Authenticated (Contributor+) Arbitrary Directory Deletion

high

The WPLMS plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary directories on the server.

CVSS:
7.1
Affected:
up to 1.9.9.5.2
Fixed in:
1.9.9.5.2
Disclosed:
Dec 17, 2024

CVE-2024-56055 on NVD →

WPLMS < 1.9.9.5.2 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete ar...

CVSS:
7.1
Affected:
up to 1.9.9.5.2
Fixed in:
1.9.9.5.2
Disclosed:
Dec 17, 2024

CVE-2024-56049 on NVD →

WPLMS < 1.9.9.5.3 - Authenticated (Instructor+) SQL Injection

medium

The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with instructor-level access and above, to append addit...

CVSS:
6.5
Affected:
up to 1.9.9.5.3
Fixed in:
1.9.9.5.3
Disclosed:
Dec 17, 2024

CVE-2024-56053 on NVD →

WPLMS < 1.9.9.5.3 - Authenticated (Subscriber+) SQL Injection

medium

The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append addit...

CVSS:
6.5
Affected:
up to 1.9.9.5.3
Fixed in:
1.9.9.5.3
Disclosed:
Dec 17, 2024

CVE-2024-56047 on NVD →

WPLMS <= 1.9.9 - Missing Authorization to Unauthenticated User Token Generation

medium

The WPLMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to generate arbitrary user tokens.

CVSS:
5.3
Affected:
up to 1.9.9
Fixed in:
1.9.9.1
Disclosed:
Dec 17, 2024

CVE-2024-56044 on NVD →

WPLMS Learning Management System for WordPress [wplms] < 4.963

unknown

[en] The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauth...

Affected:
up to 4.963
Fixed in:
4.963
Disclosed:
Nov 9, 2024

CVE-2024-10470 on NVD →

WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion

critical

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthentic...

CVSS:
9.8
Affected:
up to 4.962
Fixed in:
4.963
Disclosed:
Nov 8, 2024

CVE-2024-10470 on NVD →

WPLMS Learning Management System for WordPress [wplms] < 4.900

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.

Affected:
up to 4.900
Fixed in:
4.900
Disclosed:
Jul 11, 2023

CVE-2023-36690 on NVD →

WPLMS < 4.900 - Cross-Site Request Forgery

medium

The WPLMS theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.900. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can trick a site administrator...

CVSS:
6.3
Affected:
up to 4.900
Fixed in:
4.900
Disclosed:
Jul 5, 2023

CVE-2023-36690 on NVD →

WPLMS Learning Management System for WordPress [wplms] < 1.8.4.2

unknown

Because of this vulnerability, the attackers can have an administrator account on the target's website. Update the theme.

Affected:
up to 1.8.4.2
Fixed in:
1.8.4.2
Disclosed:
Feb 9, 2015

WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation

high

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

CVSS:
8.8
Affected:
up to 1.8.4.1
Fixed in:
1.9
Disclosed:
Feb 8, 2015

CVE-2015-10139 on NVD →

WPLMS Learning Management System for WordPress [wplms] < 1.9

unknown

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

Affected:
up to 1.9
Fixed in:
1.9
Disclosed:
Feb 8, 2015

WPLMS Learning Management System for WordPress [wplms] < 1.9

unknown

The wplms WordPress theme was affected by a Privilege Escalation security vulnerability.

Affected:
up to 1.9
Fixed in:
1.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database