PT-2026-4167 · WordPress · Wplms

Published

2026-01-22

·

Updated

2026-01-22

·

CVE-2025-69097

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions VibeThemes WPLMS versions through 1.9.9.5.4
Description The WPLMS plugin contains a flaw related to improper limitation of a pathname to a restricted directory, specifically a Path Traversal issue. This allows unauthorized access to files and directories.
Recommendations Update WPLMS to a version newer than 1.9.9.5.4

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-69097

Affected Products

Wplms