Access Control Flaw in VibeThemes WPLMS Plugin
CVE-2025-49925
7.3HIGH
What is CVE-2025-49925?
The VibeThemes WPLMS plugin suffers from a missing authorization vulnerability that allows unauthorized access to functions not adequately constrained by Access Control Lists (ACLs). This flaw may permit attackers to exploit certain functionalities of the WPLMS plugin, potentially leading to unauthorized data exposure or manipulation. The vulnerability affects all versions of the WPLMS plugin up to and including version 1.9.9.7. Website owners using this plugin are strongly advised to review their security implementations and update to a patched version to mitigate risks.
Affected Version(s)
WPLMS <= n/a