📦 Wordpress Learning Management System

by Vibethemes

🔍 What is Wordpress Learning Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-56044

CRITICAL CVSS 9.8 Dec 31, 2024

CVE-2024-56044 is an authentication bypass vulnerability in the WPLMS WordPress plugin that allows unauthenticated attackers to generate arbitrary user authentication tokens. This enables complete acc...

CVE-2024-56042

CRITICAL CVSS 9.3 Dec 31, 2024

This is an unauthenticated SQL injection vulnerability in the WPLMS WordPress plugin that allows attackers to execute arbitrary SQL commands without authentication. It affects all WordPress sites runn...

CVE-2024-56054

CRITICAL CVSS 9.1 Dec 18, 2024

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the WPLMS plugin. It affects all WordPress installations with vulnerable versions of the W...

CVE-2024-56057

CRITICAL CVSS 9.9 Dec 18, 2024

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the WPLMS plugin. It affects all WordPress installations with vulnerable versions of the W...

CVE-2024-56050

CRITICAL CVSS 9.9 Dec 18, 2024

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the WPLMS plugin. Attackers can gain full control of affected web servers. All WordPress i...

CVE-2024-56052

CRITICAL CVSS 9.9 Dec 18, 2024

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress sites running vulnerable versions of the WPLMS plugin. Attackers can achieve remote co...

CVE-2024-10470

CRITICAL CVSS 9.8 Nov 9, 2024

This vulnerability in the WPLMS WordPress theme allows unauthenticated attackers to read and delete arbitrary files on the server due to insufficient path validation. All WordPress sites using WPLMS t...

CVE-2025-49925

HIGH CVSS 7.3 Oct 22, 2025

This CVE describes a Missing Authorization vulnerability in the WPLMS WordPress plugin by VibeThemes, allowing attackers to access functionality not properly restricted by access controls. It affects ...

CVE-2024-56048

HIGH CVSS 8.8 Dec 18, 2024

This CVE describes a Missing Authorization vulnerability in the WPLMS WordPress plugin by VibeThemes that allows attackers to access functionality not properly constrained by access controls. Attacker...

CVE-2023-36690

HIGH CVSS 8.1 Jul 11, 2023

This CSRF vulnerability in the WPLMS WordPress theme allows attackers to trick authenticated administrators into performing unintended actions. It affects WordPress sites using WPLMS theme versions 4....

CVE-2025-63035

MEDIUM CVSS 6.5 Dec 9, 2025

This DOM-based XSS vulnerability in the WPLMS WordPress plugin allows attackers to inject malicious scripts into web pages viewed by other users. It affects all WordPress sites using WPLMS plugin vers...

CVE-2025-58668

MEDIUM CVSS 4.3 Sep 22, 2025

This CVE describes a missing authorization vulnerability in the WPLMS WordPress theme that allows attackers to bypass access controls. It affects all WPLMS installations running versions up to 4.970. ...