CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-56042

CVSS 9.3v3.1pub. 2024-12-31upd. 2026-04-23

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.

🤖 AI Analysis
How it works

The vulnerability results from improper sanitization of special characters in SQL queries (CWE-89). An attacker can send crafted input data directly to SQL queries executed by the plugin without needing to have any account in the system. A network attack vector without authentication and user interaction requirements means that an exploit can be conducted remotely and fully automatically.

Impact

An attacker can gain unauthorized access to sensitive data stored in the database, including user data, courses, and potentially credentials. The vulnerability may also lead to partial disruption of system availability.

Mitigation & patch

The WPLMS plugin should be updated immediately to version 1.9.9.5.3 or later. Details regarding the patch are available in the Patchstack database at the address indicated in the references. Until the update is applied, it is recommended to consider temporarily disabling the plugin.

Who is affected

WPLMS plugin (wplms_plugin) by VibeThemes for WordPress in versions from n/a to < 1.9.9.5.3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
  • Vibethemes WordPress Learning Management System

    APP
    Vibethemes
    < 1.9.9.5.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-56046CRITICAL10.0PL ✓same product

Niekontrolowane przesyłanie plików w pluginie WPLMS — upload Web Shell

CVE-2024-56043CRITICAL9.8PL ✓same product

WPLMS Plugin – nieuwierzytelniona eskalacja uprawnień (privilege escalation)

CVE-2024-56044CRITICAL9.8PL ✓same product

Authentication Bypass w pluginie WPLMS dla WordPress (do wersji 1.9.9)

CVE-2024-56045CRITICAL9.3PL ✓same product

Path Traversal w WPLMS — nieautoryzowane usuwanie katalogów

CVE-2024-56050CRITICAL9.9PL ✓same product

Nieograniczony upload plików w WPLMS — możliwość wgrania Web Shell