PT-2025-43259 · Vibethemes · Wplms+1

Rafie Muhammad

·

Published

2025-10-22

·

Updated

2025-11-18

·

CVE-2025-53420

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions VibeThemes WPLMS versions through 1.9.9.8
Description The WPLMS plugin contains a flaw related to improper input handling during web page generation, which allows for Reflected Cross-Site Scripting (XSS). This means that malicious code can be injected into web pages, potentially affecting users who view those pages. The vulnerability exists in the wplms plugin component.
Recommendations Update WPLMS to a version later than 1.9.9.8.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-53420

Affected Products

Wplms
Wordpress Learning Management System