Thème WordPress

Vulnérabilités WPLMS Learning Management System for WordPress, WordPress LMS

Cette page rassemble les failles publiées pour WPLMS Learning Management System for WordPress, WordPress LMS, leurs plages de versions affectées et les correctifs signalés dans la base locale.

18Vulnérabilités
3Critiques
18Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPLMS Learning Management System for WordPress, WordPress LMS

18 fiches

CVE-2024-56044 Moyenne · 5,3
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS <= 1.9.9 – Missing Authorization to Unauthenticated User Token Generation

The WPLMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to generate arbitrary user…

Versions affectées

*-1.9.9

Correctif

1.9.9.1

Publication

17/12/2024

CVE-2024-56045 Élevée · 8,2
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS < 1.9.9.5 – Unauthenticated Arbitrary Directory Deletion

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in all versions up to 1.9.9.5 (exclusive). This makes it possible for unauthenticated attackers…

Versions affectées

[*, 1.9.9.5)

Correctif

1.9.9.5

Publication

17/12/2024

CVE-2024-56048 Élevée · 8,8
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS <= 1.9.9 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in all versions up to, and including,…

Versions affectées

*-1.9.9

Correctif

1.9.9.1

Publication

17/12/2024

CVE-2024-56049 Élevée · 7,1
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS < 1.9.9.5.2 – Authenticated (Subscriber+) Arbitrary File Deletion

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated…

Versions affectées

[*, 1.9.9.5.2)

Correctif

1.9.9.5.2

Publication

17/12/2024

CVE-2024-56050 Élevée · 8,8
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS < 1.9.9.5.3 – Authenticated (Subscriber+) Arbitrary File Upload

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.3 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload…

Versions affectées

[*, 1.9.9.5.3)

Correctif

1.9.9.5.3

Publication

17/12/2024

CVE-2024-56052 Élevée · 8,8
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS < 1.9.9.5.2 – Authenticated (Student+) Arbitrary File Upload

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with student-level access and above, to upload…

Versions affectées

[*, 1.9.9.5.2)

Correctif

1.9.9.5.2

Publication

17/12/2024

CVE-2024-56054 Élevée · 8,8
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS < 1.9.9.5.2 – Authenticated (Instructor+) Arbitrary File Upload

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with instructor-level access and above, to upload…

Versions affectées

[*, 1.9.9.5.2)

Correctif

1.9.9.5.2

Publication

17/12/2024

CVE-2024-56055 Élevée · 7,1
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS < 1.9.9.5.2 – Authenticated (Contributor+) Arbitrary Directory Deletion

The WPLMS plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to delete…

Versions affectées

[*, 1.9.9.5.2)

Correctif

1.9.9.5.2

Publication

17/12/2024

CVE-2024-56057 Élevée · 8,8
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS < 1.9.9.5.2 – Authenticated (Contributor+) Arbitrary File Upload

The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.9.9.5.2 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to upload…

Versions affectées

[*, 1.9.9.5.2)

Correctif

1.9.9.5.2

Publication

17/12/2024

CVE-2024-10470 Critique · 9,8
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions…

Versions affectées

*-4.962

Correctif

4.963

Publication

08/11/2024

CVE-2015-10139 Élevée · 8,8
WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 – Privilege Escalation

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible…

Versions affectées

*-1.8.4.1

Correctif

1.9

Publication

08/02/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités