Sceawere

Vulnerability Detail

CVE-2026-95607UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WPLMS Blind SQL Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
VibeThemes
Product
WPLMS
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms allows Blind SQL Injection.This issue affects WPLMS : from n/a through 4.973.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-10-09T10:16:42.917Z",
  "pubdate": "2026-10-09T10:16:42.917Z",
  "executiveSummary": "A critical Blind SQL Injection vulnerability has been identified in VibeThemes WPLMS, categorized under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).\nThe vulnerability allows an unauthenticated or authenticated attacker to inject arbitrary SQL queries into the application's database backend through improper input sanitization.\nThe scope of impact is severe, potentially leading to unauthorized data exfiltration, database structure exposure, and manipulation of sensitive application data.\nThe vulnerability affects WPLMS versions ranging from n/a through 4.973.\nSuccessful exploitation requires the attacker to craft malicious SQL payloads, which are then processed by the application's backend database. This capability provides a pathway for attackers to bypass standard security controls and compromise the integrity and confidentiality of the WordPress database environment.\nGiven the nature of Blind SQL Injection, attackers can infer database content bit-by-bit by observing time-based delays or boolean-based response variations, even if the application does not directly output database results in the HTTP response.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the WPLMS codebase to properly parameterize user-supplied input or use prepared statements before executing database queries.\nThis represents a classic SQL injection flaw where special characters used in SQL syntax are not adequately neutralized. When input is concatenated directly into SQL command strings, it allows an attacker to alter the query's logic.\nIn the context of 'Blind' SQL Injection, the attacker cannot see the direct output of the query on the page. Instead, the attacker exploits the application's response behavior to infer information. This is typically achieved using two methods: Boolean-based techniques, where the attacker injects conditions to see if the page content changes (e.g., page loads normally vs. displays an error or different content), or Time-based techniques, where the attacker injects commands like 'SLEEP()' or heavy procedural queries that cause the server to delay the HTTP response if the injected condition is true.\nThe attack flow proceeds as follows: First, the attacker identifies a vulnerable endpoint or parameter within the WPLMS plugin that passes user-controlled data to a database query function. Second, the attacker crafts a malicious payload containing SQL injection primitives, such as UNION statements, subqueries, or conditional logic blocks. Third, the payload is submitted via HTTP GET or POST requests. The backend database executes the manipulated query, allowing the attacker to probe the database structure, table names, and record values.\nThe vulnerability impacts all versions of WPLMS from inception through version 4.973. It exposes the underlying WordPress database, which holds user accounts, configurations, and sensitive instructional metadata. By manipulating the backend SQL, an attacker can bypass authentication, elevate privileges, or perform unauthorized administrative actions.\nThe lack of prepared statements or robust database abstraction layer usage in the affected WPLMS components is the primary failure point. This allows the database driver to misinterpret user input as executable code rather than literal data. Without strict input validation or the implementation of an allow-list for expected input patterns, the application remains susceptible to advanced query manipulation techniques used in modern automated exploit frameworks."
}
CVE-2026-95607: WPLMS Blind SQL Injection Vulnerability (HIGH Severity, CVSS: 8.5) | Sceawere