WPLMS <= 4.970 - Missing Authorization
medium
The WPLMS theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.970. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 5.4
- Affected:
- up to 4.970
- Fixed in:
- 4.971
- Disclosed:
- Sep 22, 2025
CVE-2025-58668 on NVD →
WPLMS Learning Management System for WordPress [wplms] < 1.9
unknown
[en] The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Jul 19, 2025
CVE-2015-10139 on NVD →
WPLMS <= 1.9.9 - Unauthenticated Arbitrary File Upload
critical
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server whic...
- CVSS:
- 9.8
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9.1
- Disclosed:
- Dec 17, 2024
CVE-2024-56046 on NVD →
WPLMS <= 1.9.9 - Unauthenticated Privilege Escalation
critical
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to gain elevated access to a site.
- CVSS:
- 9.8
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9.1
- Disclosed:
- Dec 17, 2024
CVE-2024-56043 on NVD →
WPLMS < 1.9.9.5.2 - Authenticated (Student+) Arbitrary File Upload
high
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with student-level access and above, to upload arbitrary files on the affected site's server which may make remote c...
- CVSS:
- 8.8
- Affected:
- up to 1.9.9.5.2
- Fixed in:
- 1.9.9.5.2
- Disclosed:
- Dec 17, 2024
CVE-2024-56052 on NVD →
WPLMS < 1.9.9.5 - Authenticated (Student+) Remote Code Execution
high
The WPLMS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.9.9.5 (exclusive). This makes it possible for authenticated attackers, with student-level access and above, to execute code on the server.
- CVSS:
- 8.8
- Affected:
- up to 1.9.9.5
- Fixed in:
- 1.9.9.5
- Disclosed:
- Dec 17, 2024
CVE-2024-56051 on NVD →
WPLMS < 1.9.9.5.3 - Authenticated (Subscriber+) Arbitrary File Upload
high
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.3 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remot...
- CVSS:
- 8.8
- Affected:
- up to 1.9.9.5.3
- Fixed in:
- 1.9.9.5.3
- Disclosed:
- Dec 17, 2024
CVE-2024-56050 on NVD →
WPLMS <= 1.9.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
high
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in all versions up to, and including, 1.9.9. This makes it possible for authenticated attackers, with Subscribe...
- CVSS:
- 8.8
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9.1
- Disclosed:
- Dec 17, 2024
CVE-2024-56048 on NVD →
WPLMS < 1.9.9.5.2 - Authenticated (Instructor+) Arbitrary File Upload
high
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with instructor-level access and above, to upload arbitrary files on the affected site's server which may make remot...
- CVSS:
- 8.8
- Affected:
- up to 1.9.9.5.2
- Fixed in:
- 1.9.9.5.2
- Disclosed:
- Dec 17, 2024
CVE-2024-56054 on NVD →
WPLMS < 1.9.9.5.2 - Authenticated (Contributor+) Arbitrary File Upload
high
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remo...
- CVSS:
- 8.8
- Affected:
- up to 1.9.9.5.2
- Fixed in:
- 1.9.9.5.2
- Disclosed:
- Dec 17, 2024
CVE-2024-56057 on NVD →
WPLMS < 1.9.9.5 - Unauthenticated Arbitrary Directory Deletion
high
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in all versions up to 1.9.9.5 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary directories on the server.
- CVSS:
- 8.2
- Affected:
- up to 1.9.9.5
- Fixed in:
- 1.9.9.5
- Disclosed:
- Dec 17, 2024
CVE-2024-56045 on NVD →
WPLMS < 1.9.9.5.2 - Authenticated (Contributor+) Arbitrary Directory Deletion
high
The WPLMS plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary directories on the server.
- CVSS:
- 7.1
- Affected:
- up to 1.9.9.5.2
- Fixed in:
- 1.9.9.5.2
- Disclosed:
- Dec 17, 2024
CVE-2024-56055 on NVD →
WPLMS < 1.9.9.5.2 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete ar...
- CVSS:
- 7.1
- Affected:
- up to 1.9.9.5.2
- Fixed in:
- 1.9.9.5.2
- Disclosed:
- Dec 17, 2024
CVE-2024-56049 on NVD →
WPLMS < 1.9.9.5.3 - Authenticated (Instructor+) SQL Injection
medium
The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with instructor-level access and above, to append addit...
- CVSS:
- 6.5
- Affected:
- up to 1.9.9.5.3
- Fixed in:
- 1.9.9.5.3
- Disclosed:
- Dec 17, 2024
CVE-2024-56053 on NVD →
WPLMS < 1.9.9.5.3 - Authenticated (Subscriber+) SQL Injection
medium
The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append addit...
- CVSS:
- 6.5
- Affected:
- up to 1.9.9.5.3
- Fixed in:
- 1.9.9.5.3
- Disclosed:
- Dec 17, 2024
CVE-2024-56047 on NVD →
WPLMS <= 1.9.9 - Missing Authorization to Unauthenticated User Token Generation
medium
The WPLMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to generate arbitrary user tokens.
- CVSS:
- 5.3
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9.1
- Disclosed:
- Dec 17, 2024
CVE-2024-56044 on NVD →
WPLMS Learning Management System for WordPress [wplms] < 4.963
unknown
[en] The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauth...
- Affected:
- up to 4.963
- Fixed in:
- 4.963
- Disclosed:
- Nov 9, 2024
CVE-2024-10470 on NVD →
WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
critical
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthentic...
- CVSS:
- 9.8
- Affected:
- up to 4.962
- Fixed in:
- 4.963
- Disclosed:
- Nov 8, 2024
CVE-2024-10470 on NVD →
WPLMS Learning Management System for WordPress [wplms] < 4.900
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
- Affected:
- up to 4.900
- Fixed in:
- 4.900
- Disclosed:
- Jul 11, 2023
CVE-2023-36690 on NVD →
WPLMS < 4.900 - Cross-Site Request Forgery
medium
The WPLMS theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.900. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can trick a site administrator...
- CVSS:
- 6.3
- Affected:
- up to 4.900
- Fixed in:
- 4.900
- Disclosed:
- Jul 5, 2023
CVE-2023-36690 on NVD →
WPLMS Learning Management System for WordPress [wplms] < 1.8.4.2
unknown
Because of this vulnerability, the attackers can have an administrator account on the target's website.
Update the theme.
- Affected:
- up to 1.8.4.2
- Fixed in:
- 1.8.4.2
- Disclosed:
- Feb 9, 2015
WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation
high
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
- CVSS:
- 8.8
- Affected:
- up to 1.8.4.1
- Fixed in:
- 1.9
- Disclosed:
- Feb 8, 2015
CVE-2015-10139 on NVD →
WPLMS Learning Management System for WordPress [wplms] < 1.9
unknown
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Feb 8, 2015
WPLMS Learning Management System for WordPress [wplms] < 1.9
unknown
The wplms WordPress theme was affected by a Privilege Escalation security vulnerability.
- Affected:
- up to 1.9
- Fixed in:
- 1.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database