Access Control Flaw in VibeThemes WPLMS Plugin
CVE-2025-49925

7.3HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 October 2025

What is CVE-2025-49925?

The VibeThemes WPLMS plugin suffers from a missing authorization vulnerability that allows unauthorized access to functions not adequately constrained by Access Control Lists (ACLs). This flaw may permit attackers to exploit certain functionalities of the WPLMS plugin, potentially leading to unauthorized data exposure or manipulation. The vulnerability affects all versions of the WPLMS plugin up to and including version 1.9.9.7. Website owners using this plugin are strongly advised to review their security implementations and update to a patched version to mitigate risks.

Affected Version(s)

WPLMS <= n/a

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.