SQL Injection Vulnerability in VibeThemes WPLMS Plugin
CVE-2026-96327

9.3CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-96327?

The VibeThemes WPLMS plugin for WordPress contains a vulnerability that permits attackers to execute Blind SQL Injection. This flaw arises from improper neutralization of special elements utilized in SQL commands, potentially enabling unauthorized actions on the database. Affected installations of WPLMS prior to version 1.9.9.8.2 are especially vulnerable. Website administrators should promptly update to the latest version to mitigate the risks associated with this security issue.

Affected Version(s)

WPLMS 0 < 1.9.9.8.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad | Patchstack Bug Bounty Program
.