PT-2025-50042 · Vibethemes+1 · Wplms+1

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-63035

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WPLMS versions prior to 1.9.9.5.5
Description The wplms plugin in VibeThemes WPLMS contains an issue where improper neutralization of input during web page generation allows for DOM-Based Cross-site Scripting (XSS), a flaw where the application contains client-side JavaScript that processes data from an untrusted source in an unsafe way, typically by writing the data to the Document Object Model (DOM).
Recommendations Update to a version later than 1.9.9.5.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63035

Affected Products

Wplms
Wordpress Learning Management System