Access Control Flaw in VibeThemes WPLMS Plugin
CVE-2025-49925
What is CVE-2025-49925?
The VibeThemes WPLMS plugin suffers from a missing authorization vulnerability that allows unauthorized access to functions not adequately constrained by Access Control Lists (ACLs). This flaw may permit attackers to exploit certain functionalities of the WPLMS plugin, potentially leading to unauthorized data exposure or manipulation. The vulnerability affects all versions of the WPLMS plugin up to and including version 1.9.9.7. Website owners using this plugin are strongly advised to review their security implementations and update to a patched version to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPLMS <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved