Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms allows Blind SQL Injection.This issue affects WPLMS : from n/a through 4.973.
Published: 2026-10-09
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: database compromise
Action: Immediate Patch
AI Analysis

Impact

Improper neutralization of special elements used in an SQL command enables a blind SQL injection in the WordPress WPLMS theme. The flaw arises from the theme’s handling of user‑supplied input, allowing an attacker to manipulate SQL statements sent to the database. Although the injection is blind, the attacker can infer query success and recover data, or modify and delete records, thereby exposing user information and corrupting application data.

Affected Systems

The affected product is the WordPress WPLMS theme from VibeThemes. Versions from the earliest available build through 4.973, inclusive, are vulnerable. Any site running one of these releases without applying the newer 4.974 or later patch is exposed.

Risk and Exploitability

With a CVSS score of 8.5, the flaw is rated high severity. The EPSS score is not available, and it has not been listed in the CISA KEV catalog. The likely attack vector is a blind SQL injection that an attacker can trigger by supplying crafted input to the theme’s forms or URL parameters. Because the vulnerability does not require authentication, a publicly accessible input point can be exploited without additional permissions, making the threat realistic for external attackers.

Generated by OpenCVE AI on October 9, 2026 at 11:48 UTC.

Remediation

Vendor Solution

Update the WordPress WPLMS theme to the latest available version (at least 4.974).


OpenCVE Recommended Actions

  • Upgrade the WPLMS theme to version 4.974 or later.
  • If an immediate upgrade is not possible, restrict the theme’s database permissions by limiting the user role that the theme uses to connect, or apply firewall rules that block unauthorized SQL query patterns from the theme’s endpoints.
  • Audit all user-supplied inputs in the theme and ensure they are passed to the database through parameterized queries or properly escaped to eliminate injection vectors.
  • Consider monitoring database activity for anomalous query patterns as an additional early warning mechanism.

Generated by OpenCVE AI on October 9, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms allows Blind SQL Injection.This issue affects WPLMS : from n/a through 4.973.
Title WordPress WPLMS theme <= 4.973 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:18.459Z

Reserved: 2026-09-22T09:18:20.380Z

Link: CVE-2026-95607

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:42.917

Modified: 2026-10-09T10:16:42.917

Link: CVE-2026-95607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:00:07Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')