What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
What the vulnerability does
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
Explanation of Vulnerability in Simple Terms
WPLMS versions up to 1.9.9.5.2 contain a vulnerability allowing authenticated users with low privileges to modify site data and cause service disruption. The flaw affects the entire site scope due to changed scope conditions. No confidentiality impact occurs, but integrity and availability are compromised. Administrators should update to a version newer than 1.9.9.5.2.
What an attacker can do
Modify site data and cause the site to become unavailable or unresponsive.
Potential impact on your site
Authenticated users can deface content, disrupt service, or make the site unavailable to visitors.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or student role).
Key dates
External resources
Related vulnerabilities