Impact
The vulnerability in the VibeThemes WPLMS plugin is a reflected cross‑site scripting flaw stemming from inadequate sanitization of user input. An attacker can embed arbitrary JavaScript within request parameters that the plugin outputs without proper encoding, leading to client‑side script execution in the victim’s browser. The weakness, classified as CWE‑79, carries a CVSS score of 7.1, which is considered high severity. This can enable session hijacking, data theft, or site defacement when a user clicks a malicious link or submits a crafted form.
Affected Systems
The VibeThemes WPLMS plugin is affected for all releases up through and including version 1.9.9.8. Any WordPress site that has installed an older version of the plugin is vulnerable.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. However, the high CVSS score and lack of privilege escalation mean that any authenticated or unauthenticated user who visits a crafted URL can trigger attacker‑controlled script execution. The attack requires only a vulnerable URL and a victim who interacts with it; no special access or additional software is necessary.
OpenCVE Enrichment