Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
The vulnerability results from improper sanitization of special characters in SQL queries (CWE-89). An attacker can send crafted input data directly to SQL queries executed by the plugin without needing to have any account in the system. A network attack vector without authentication and user interaction requirements means that an exploit can be conducted remotely and fully automatically.
An attacker can gain unauthorized access to sensitive data stored in the database, including user data, courses, and potentially credentials. The vulnerability may also lead to partial disruption of system availability.
The WPLMS plugin should be updated immediately to version 1.9.9.5.3 or later. Details regarding the patch are available in the Patchstack database at the address indicated in the references. Until the update is applied, it is recommended to consider temporarily disabling the plugin.
WPLMS plugin (wplms_plugin) by VibeThemes for WordPress in versions from n/a to < 1.9.9.5.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:LVibethemes WordPress Learning Management System
APPVibethemes< 1.9.9.5.3
Related vulnerabilities
Niekontrolowane przesyłanie plików w pluginie WPLMS — upload Web Shell
WPLMS Plugin – nieuwierzytelniona eskalacja uprawnień (privilege escalation)
Authentication Bypass w pluginie WPLMS dla WordPress (do wersji 1.9.9)
Path Traversal w WPLMS — nieautoryzowane usuwanie katalogów
Nieograniczony upload plików w WPLMS — możliwość wgrania Web Shell