PT-2025-30133 · WordPress · Wplms

Published

2025-07-19

·

Updated

2025-12-16

·

CVE-2015-10139

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPLMS versions 1.5.2 through 1.8.4.1
Description The WPLMS theme for WordPress is susceptible to privilege escalation via the wp ajax import data API endpoint. Authenticated attackers can modify restricted settings and potentially create a new accessible admin account.
Recommendations Update WPLMS to a version later than 1.8.4.1.

Exploit

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2015-10139

Affected Products

Wplms