CVE-2015-10139

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vibethemes:wordpress_learning_management_system_:*:*:*:*:*:wordpress:*:*

History

16 Dec 2025, 15:49

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/130291/ - () https://packetstormsecurity.com/files/130291/ - Exploit, Third Party Advisory
References () https://themeforest.net/item/wplms-learning-management-system/6780226 - () https://themeforest.net/item/wplms-learning-management-system/6780226 - Product
References () https://twitter.com/_wpscan_/status/564874637679820800?lang=ca - () https://twitter.com/_wpscan_/status/564874637679820800?lang=ca - Broken Link
References () https://wpscan.com/vulnerability/7785 - () https://wpscan.com/vulnerability/7785 - Broken Link
References () https://www.rapid7.com/db/modules/auxiliary/admin/http/wp_wplms_privilege_escalation/ - () https://www.rapid7.com/db/modules/auxiliary/admin/http/wp_wplms_privilege_escalation/ - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/6e0e8f5f-8216-4276-a810-860f9b52c447?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/6e0e8f5f-8216-4276-a810-860f9b52c447?source=cve - Third Party Advisory
CPE cpe:2.3:a:vibethemes:wordpress_learning_management_system_:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
First Time Vibethemes
Vibethemes wordpress Learning Management System

22 Jul 2025, 13:06

Type Values Removed Values Added
Summary
  • (es) El tema WPLMS para WordPress es vulnerable a la escalada de privilegios en las versiones 1.5.2 a 1.8.4.1 mediante la acción AJAX 'wp_ajax_import_data'. Esto permite a atacantes autenticados modificar configuraciones que de otro modo estarían restringidas y, potencialmente, crear una nueva cuenta de administrador accesible.

19 Jul 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-19 12:15

Updated : 2025-12-16 15:49


NVD link : CVE-2015-10139

Mitre link : CVE-2015-10139

CVE.ORG link : CVE-2015-10139


JSON object : View

Products Affected

vibethemes

  • wordpress_learning_management_system_
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo