CVE-2015-10139: Vibethemes WordPress Learning Management System

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

Affected products

  • Vibethemes WordPress Learning Management System: from 1.5.2, before 1.8.9 (fixed in 1.8.9)

Published 2025-07-19. Last modified 2026-06-17.