Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
The vulnerability consists of improper sanitization of file paths — an attacker can provide a crafted string in the format '.../...//' (a technique to bypass simple filters blocking '../'), which after processing by the application leads to the specified directory outside the main plugin directory. This mechanism allows operations outside the permitted area of the server's file system. The attack is possible without any authentication and is performed remotely over the network.
An attacker can delete any directories accessible in the context of the web server's permissions, which may lead to service unavailability (DoS), damage to the WordPress installation, or destruction of application data. It is also possible to compromise the integrity of the server's file system.
The WPLMS plugin must be updated immediately to version 1.9.9.5 or newer. Patch details are available in the Patchstack database and in the WordPress plugin repository.
WPLMS plugin (wplms_plugin) by VibeThemes for WordPress — versions from unspecified (n/a) to versions below 1.9.9.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:HVibethemes WordPress Learning Management System
APPVibethemes< 1.9.9.5
Related vulnerabilities
Niekontrolowane przesyłanie plików w pluginie WPLMS — upload Web Shell
SQL Injection w pluginie WPLMS dla WordPress (VibeThemes)
WPLMS Plugin – nieuwierzytelniona eskalacja uprawnień (privilege escalation)
Authentication Bypass w pluginie WPLMS dla WordPress (do wersji 1.9.9)
Nieograniczony upload plików w WPLMS — możliwość wgrania Web Shell