What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
What the vulnerability does
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
Explanation of Vulnerability in Simple Terms
WPLMS versions up to 1.9.9.5 contain a vulnerability allowing network-based attackers to modify site content and disrupt service without authentication. The attack requires no user interaction and can affect systems beyond the vulnerable component. No confidentiality impact is present, but integrity and availability are compromised.
What an attacker can do
Modify site content and cause service disruption without logging in.
Potential impact on your site
Attackers can alter pages, posts, or settings and make the site unavailable without needing valid credentials.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities