VibeThemes WPLMS
cpe:2.3:a:vibethemes:wordpress_learning_management_system_:*:*:*:*:wordpress:*:*
- <= 1.9.9.5.4
A path traversal vulnerability has been identified in the VibeThemes WPLMS plugin, specifically in versions through 1.9.9.5.4. This vulnerability allows for improper limitation of a pathname, enabling arbitrary file deletion on the affected WordPress sites.
Exploitation of this vulnerability could lead to arbitrary file deletion, allowing malicious actors to remove files from the website. Deleting core files could disrupt the site's functionality, causing it to break or stop working altogether.
Users are advised to update to a version of the VibeThemes WPLMS plugin that is not vulnerable. Patchstack has issued a mitigation rule to block attacks targeting this vulnerability until an official fix is available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.