Two WordPress plugins required by the premium WordPress WPLMS themeare vulnerable to more than a dozen critical vulnerabilities.

The vulnerabilities are considered critical as they could allow a remote, unauthorized attacker to upload arbitrary files to the server, execute code, escalate privileges to administrator level, and perform SQL injections.
The WordPress WPLMS theme is a learning management system (LMS) for WordPress and is primarily used by educational institutions, training companies, and e-learning providers. It has over 28,000 sales.
See also: RCE vulnerability in 1,000,000 WordPress sites allows backend control
Critical vulnerabilities in WordPress WPLMS theme
Patchstack researchers discovered 18 bugs in the WPLMS and VibeBP plugins and presented the 10 most important ones.
WPLMS vulnerabilities:
CVE-2024-56042 (CVSS 9.3/10): Attackers can inject malicious SQL queries to extract sensitive data or compromise the database.
CVE-2024-56043 (CVSS 9.8/10): This vulnerability allows attackers to register as any role, including Administrator, without authentication.
CVE-2024-56046 (CVSS 10.0/10): Allows malicious file upload without authentication, potentially leading to remote code execution (RCE).
CVE-2024-56047 (CVSS 8.5/10): With this vulnerability, low-privileged users can execute SQL queries, compromising the integrity or confidentiality of data.
CVE-2024-56048 (CVSS 8.8/10): Users with low privileges can be elevated to higher roles (e.g. Administrator).
CVE-2024-56050 (CVSS 9.9/10): Authorized users with subscriber privileges can upload files, bypassing restrictions.
CVE-2024-56052 (CVSS 9.9/10): Similar to Subscriber+ but exploitable by users with student roles.
VibeBP vulnerabilities:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
CVE-2024-56039 (CVSS 9.3/10): SQL queries can be injected by unauthenticated users.
CVE-2024-56040 (CVSS 9.8/10): Attackers can register as privileged users without authentication.
CVE-2024-56041 (CVSS 8.5/10): Authorized users with minimal privileges can perform SQL injection to compromise or extract database.
See also: 390,000 WordPress accounts stolen by hackers
WordPress WPLMS theme users should upgrade to version 1.9.9.5.3 or later , while VibeBP should be upgraded to version 1.9.9.7.7 or later.
Patchstack discovered the vulnerabilities on March 31 and notified Vibe Themes , the developer of WPLMS. Between April and November, the developer tested several updates until it was able to patch all the vulnerabilities.

WordPress Security
WordPress website security requires a multi-pronged approach to protect against potential threats. One of the key strategies includes regularly updating plugins and themes (e.g. WPLMS) to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect data in the event of an attack.
It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware scanning, and brute force attack prevention.
By implementing these measures, you can significantly improve the security of your WordPress website.
See also: Woffice: Vulnerabilities in WordPress theme – Update now!
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
source: www.bleepingcomputer.com
