SQL Injection Vulnerability in VibeThemes WPLMS Plugin
CVE-2026-96327
9.3CRITICAL
What is CVE-2026-96327?
The VibeThemes WPLMS plugin for WordPress contains a vulnerability that permits attackers to execute Blind SQL Injection. This flaw arises from improper neutralization of special elements utilized in SQL commands, potentially enabling unauthorized actions on the database. Affected installations of WPLMS prior to version 1.9.9.8.2 are especially vulnerable. Website administrators should promptly update to the latest version to mitigate the risks associated with this security issue.
Affected Version(s)
WPLMS 0 < 1.9.9.8.2