Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Blind SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.8.2.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: SQL Injection (Data Compromise)
Action: Patch
AI Analysis

Impact

The vulnerability is a classic blind SQL injection flaw in the VibeThemes WPLMS WordPress plugin. Improper neutralization of special characters when building SQL statements allows an attacker to inject arbitrary queries. Depending on the privileges of the database user that WordPress uses, this could lead to reading, modifying, or deleting sensitive data, and in some configurations could even enable remote code execution if the database account has high privileges. The high CVSS score of 9.3 reflects the critical nature of this flaw and its potential to compromise the entire data store.

Affected Systems

All WordPress sites that have installed the VibeThemes WPLMS plugin in a version older than 1.9.9.8.2 are impacted. The issue arises anywhere database queries are constructed without proper parameterization within the plugin’s codebase. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score places the flaw in the Critical severity range. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no documented active exploitation so far. The likely attack vector is remote, via the plugin’s front‑end or admin interfaces, and requires only network access to the WordPress site. An attacker could craft malicious input to the vulnerable endpoint and trigger the blind SQL injection, potentially reading or altering data.

Generated by OpenCVE AI on October 9, 2026 at 12:09 UTC.

Remediation

Vendor Solution

Update the WordPress WPLMS plugin to the latest available version (at least 1.9.9.8.2).


OpenCVE Recommended Actions

  • Update the WordPress WPLMS plugin to version 1.9.9.8.2 or later, which contains the fix for the SQL injection vulnerability.
  • If an immediate update is not possible, reduce the database user’s privileges to only the minimum required by WordPress, removing write or privileged capabilities that could be abused.
  • Deploy a web application firewall with rules that detect and block SQL injection patterns targeting the WPLMS plugin endpoints.
  • Monitor WordPress and database logs for unusual query activity, and investigate any suspicious entries promptly.

Generated by OpenCVE AI on October 9, 2026 at 12:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Blind SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.8.2.
Title WordPress WPLMS plugin < 1.9.9.8.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:18.114Z

Reserved: 2026-09-22T23:00:10.419Z

Link: CVE-2026-96327

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:43.460

Modified: 2026-10-09T10:16:43.460

Link: CVE-2026-96327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:15:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')