Thème WordPress
Vulnérabilités WPLMS Learning Management System for WordPress, WordPress LMS
Cette page rassemble les failles publiées pour WPLMS Learning Management System for WordPress, WordPress LMS, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPLMS Learning Management System for WordPress, WordPress LMS
18 fiches
WPLMS <= 4.970 – Missing Authorization
The WPLMS theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.970. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-4.970
4.971
22/09/2025
WPLMS <= 1.9.9 – Unauthenticated Privilege Escalation
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to gain elevated access to a…
*-1.9.9
1.9.9.1
17/12/2024
WPLMS <= 1.9.9 – Missing Authorization to Unauthenticated User Token Generation
The WPLMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to generate arbitrary user…
*-1.9.9
1.9.9.1
17/12/2024
WPLMS < 1.9.9.5 – Unauthenticated Arbitrary Directory Deletion
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in all versions up to 1.9.9.5 (exclusive). This makes it possible for unauthenticated attackers…
[*, 1.9.9.5)
1.9.9.5
17/12/2024
WPLMS <= 1.9.9 – Unauthenticated Arbitrary File Upload
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated…
*-1.9.9
1.9.9.1
17/12/2024
WPLMS < 1.9.9.5.3 – Authenticated (Subscriber+) SQL Injection
The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
[*, 1.9.9.5.3)
1.9.9.5.3
17/12/2024
WPLMS <= 1.9.9 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in all versions up to, and including,…
*-1.9.9
1.9.9.1
17/12/2024
WPLMS < 1.9.9.5.2 – Authenticated (Subscriber+) Arbitrary File Deletion
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated…
[*, 1.9.9.5.2)
1.9.9.5.2
17/12/2024
WPLMS < 1.9.9.5.3 – Authenticated (Subscriber+) Arbitrary File Upload
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.3 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload…
[*, 1.9.9.5.3)
1.9.9.5.3
17/12/2024
WPLMS < 1.9.9.5.2 – Authenticated (Student+) Arbitrary File Upload
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with student-level access and above, to upload…
[*, 1.9.9.5.2)
1.9.9.5.2
17/12/2024
WPLMS < 1.9.9.5.2 – Authenticated (Instructor+) Arbitrary File Upload
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with instructor-level access and above, to upload…
[*, 1.9.9.5.2)
1.9.9.5.2
17/12/2024
WPLMS < 1.9.9.5.2 – Authenticated (Contributor+) Arbitrary Directory Deletion
The WPLMS plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to delete…
[*, 1.9.9.5.2)
1.9.9.5.2
17/12/2024
WPLMS < 1.9.9.5.2 – Authenticated (Contributor+) Arbitrary File Upload
The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to upload…
[*, 1.9.9.5.2)
1.9.9.5.2
17/12/2024
WPLMS < 1.9.9.5 – Authenticated (Student+) Remote Code Execution
The WPLMS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.9.9.5 (exclusive). This makes it possible for authenticated attackers, with student-level access and above, to execute code on the server.
[*, 1.9.9.5)
1.9.9.5
17/12/2024
WPLMS < 1.9.9.5.3 – Authenticated (Instructor+) SQL Injection
The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
[*, 1.9.9.5.3)
1.9.9.5.3
17/12/2024
WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions…
*-4.962
4.963
08/11/2024
WPLMS < 4.900 – Cross-Site Request Forgery
The WPLMS theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.900. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to…
[*, 4.900)
4.900
05/07/2023
WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 – Privilege Escalation
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible…
*-1.8.4.1
1.9
08/02/2015
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.