Impact
The WPLMS plugin for WordPress contains a missing authorization flaw that allows users to access functions that should be restricted by access control lists. This issue, identified as CWE‑862, results in the ability to execute privileged operations without proper permission checks, potentially exposing sensitive course data or administrative capabilities. The vulnerability could enable an attacker to create, modify, or delete learning objects and user information within the platform.
Affected Systems
VibeThemes' WPLMS WordPress plugin, which is embedded in WordPress sites, is affected. All installations using versions from the initial release through 1.9.9.7 are susceptible. Users running the plugin on any WordPress instance must verify their current version against the stated range.
Risk and Exploitability
The CVSS score of 7.5 indicates a substantial severity, while the EPSS score of less than 1% suggests exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widescale exploitation yet. Likely attack vectors involve web requests directly targeting plugin endpoints; any authenticated user or potentially unauthenticated user with access to those routes could exploit the missing access checks to gain unauthorized privileges.
OpenCVE Enrichment