Impact
The vulnerability is a classic blind SQL injection flaw in the VibeThemes WPLMS WordPress plugin. Improper neutralization of special characters when building SQL statements allows an attacker to inject arbitrary queries. Depending on the privileges of the database user that WordPress uses, this could lead to reading, modifying, or deleting sensitive data, and in some configurations could even enable remote code execution if the database account has high privileges. The high CVSS score of 9.3 reflects the critical nature of this flaw and its potential to compromise the entire data store.
Affected Systems
All WordPress sites that have installed the VibeThemes WPLMS plugin in a version older than 1.9.9.8.2 are impacted. The issue arises anywhere database queries are constructed without proper parameterization within the plugin’s codebase. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score places the flaw in the Critical severity range. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no documented active exploitation so far. The likely attack vector is remote, via the plugin’s front‑end or admin interfaces, and requires only network access to the WordPress site. An attacker could craft malicious input to the vulnerable endpoint and trigger the blind SQL injection, potentially reading or altering data.
OpenCVE Enrichment