Description
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.7.
Published: 2025-10-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPLMS plugin for WordPress contains a missing authorization flaw that allows users to access functions that should be restricted by access control lists. This issue, identified as CWE‑862, results in the ability to execute privileged operations without proper permission checks, potentially exposing sensitive course data or administrative capabilities. The vulnerability could enable an attacker to create, modify, or delete learning objects and user information within the platform.

Affected Systems

VibeThemes' WPLMS WordPress plugin, which is embedded in WordPress sites, is affected. All installations using versions from the initial release through 1.9.9.7 are susceptible. Users running the plugin on any WordPress instance must verify their current version against the stated range.

Risk and Exploitability

The CVSS score of 7.5 indicates a substantial severity, while the EPSS score of less than 1% suggests exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widescale exploitation yet. Likely attack vectors involve web requests directly targeting plugin endpoints; any authenticated user or potentially unauthenticated user with access to those routes could exploit the missing access checks to gain unauthorized privileges.

Generated by OpenCVE AI on April 30, 2026 at 05:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WPLMS plugin to the latest available version (≥ 1.9.9.8) or apply the vendor’s official patch
  • Restrict access to the plugin’s management routes by configuring WordPress role permissions, ensuring only users with appropriate privileges can invoke restricted functions
  • Implement monitoring of web logs and plugin audit trails to detect and respond to unauthorized access attempts

Generated by OpenCVE AI on April 30, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 12 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Vibethemes
Vibethemes wordpress Learning Management System
CPEs cpe:2.3:a:vibethemes:wordpress_learning_management_system:*:*:*:*:*:wordpress:*:*
Vendors & Products Vibethemes
Vibethemes wordpress Learning Management System

Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.7.
Title WordPress WPLMS plugin <= 1.9.9.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Vibethemes Wordpress Learning Management System
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:07.976Z

Reserved: 2025-06-11T16:07:08.210Z

Link: CVE-2025-49925

cve-icon Vulnrichment

Updated: 2025-10-23T15:28:20.693Z

cve-icon NVD

Status : Modified

Published: 2025-10-22T15:15:38.460

Modified: 2026-04-27T20:16:17.907

Link: CVE-2025-49925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:45:16Z

Weaknesses