logo

Premium WPLMS WordPress plugins address seven critical flaws

ID: 1a835b48-0f16-59a0-a918-733fe43b2887

STIX ID: report--1a835b48-0f16-59a0-a918-733fe43b2887

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-23

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Patchstack disclosed multiple critical vulnerabilities in the WPLMS WordPress theme and VibeBP plugin—18 issues in total with several high/critical CVEs (including CVE-2024-56046 for unauthenticated file upload leading to potential RCE, privilege escalation, and SQL injection). Users are advised to upgrade WPLMS to ≥1.9.9.5.3 and VibeBP to ≥1.9.9.7.7; Patchstack and Vibe Themes collaborated on patches and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.