CVE-2026-96327: Vibethemes Wplms
Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Blind SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.8.2.
Affected products
- Vibethemes Wplms: before 1.9.9.8.2 (fixed in 1.9.9.8.2)
Published 2026-10-09. Last modified 2026-10-09.