CVE-2015-10139: Vibethemes WordPress Learning Management System
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
Affected products
- Vibethemes WordPress Learning Management System: from 1.5.2, before 1.8.9 (fixed in 1.8.9)
Published 2025-07-19. Last modified 2026-06-17.