What the vulnerability does
01Description
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.
Explanation of Vulnerability in Simple Terms
WPLMS versions up to 1.9.9 lack proper authorization checks, allowing authenticated users with low privileges to read, modify, or delete sensitive data and functionality. An attacker with a basic user account can perform actions restricted to administrators or instructors without additional verification. This affects the core learning management system operations and user data integrity.
What an attacker can do
Read, modify, or delete sensitive data and perform administrative actions with a low-privilege user account.
Potential impact on your site
Student or subscriber accounts can access course content, grades, and user data they shouldn't, or modify course settings.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site; no additional user interaction required.
Key dates
External resources
Related vulnerabilities