Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-9398 | The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account. |
Tue, 16 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vibethemes
Vibethemes wordpress Learning Management System |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:vibethemes:wordpress_learning_management_system_:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Vibethemes
Vibethemes wordpress Learning Management System |
Mon, 21 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 19 Jul 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account. | |
| Title | WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation | |
| Weaknesses | CWE-269 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:59:36.412Z
Reserved: 2025-07-18T21:32:11.260Z
Link: CVE-2015-10139
Updated: 2025-07-21T15:41:20.288Z
Status : Analyzed
Published: 2025-07-19T12:15:35.127
Modified: 2025-12-16T15:49:59.177
Link: CVE-2015-10139
No data.
OpenCVE Enrichment
No data.
EUVD