PT-2025-50042 · Vibethemes+1 · Wplms+1
Published
2025-12-09
·
Updated
2025-12-09
·
CVE-2025-63035
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WPLMS versions prior to 1.9.9.5.5
Description
The
wplms plugin in VibeThemes WPLMS contains an issue where improper neutralization of input during web page generation allows for DOM-Based Cross-site Scripting (XSS), a flaw where the application contains client-side JavaScript that processes data from an untrusted source in an unsafe way, typically by writing the data to the Document Object Model (DOM).Recommendations
Update to a version later than 1.9.9.5.4.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wplms
Wordpress Learning Management System