SQL Injection Vulnerability in VibeThemes WPLMS Product
CVE-2026-95607
8.5HIGH
What is CVE-2026-95607?
The vulnerability identified in VibeThemes WPLMS products allows for a blind SQL injection due to improper neutralization of special elements used in SQL commands. This issue could potentially enable attackers to manipulate database queries, exposing sensitive data and compromising the integrity of affected installations. Users of WPLMS versions up to 4.973 are urged to take immediate action to secure their sites against unauthorized access and data breaches.
Affected Version(s)
WPLMS 0 <= 4.973