Impact
Improper neutralization of special elements used in an SQL command enables a blind SQL injection in the WordPress WPLMS theme. The flaw arises from the theme’s handling of user‑supplied input, allowing an attacker to manipulate SQL statements sent to the database. Although the injection is blind, the attacker can infer query success and recover data, or modify and delete records, thereby exposing user information and corrupting application data.
Affected Systems
The affected product is the WordPress WPLMS theme from VibeThemes. Versions from the earliest available build through 4.973, inclusive, are vulnerable. Any site running one of these releases without applying the newer 4.974 or later patch is exposed.
Risk and Exploitability
With a CVSS score of 8.5, the flaw is rated high severity. The EPSS score is not available, and it has not been listed in the CISA KEV catalog. The likely attack vector is a blind SQL injection that an attacker can trigger by supplying crafted input to the theme’s forms or URL parameters. Because the vulnerability does not require authentication, a publicly accessible input point can be exploited without additional permissions, making the threat realistic for external attackers.
OpenCVE Enrichment