Sceawere

Vulnerability Detail

CVE-2026-96327UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Blind SQL Injection in WPLMS

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
3h ago
Vendor
VibeThemes
Product
WPLMS
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Blind SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.8.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-10-09T10:16:43.460Z",
  "pubdate": "2026-10-09T10:16:43.460Z",
  "executiveSummary": "The WPLMS plugin for WordPress is susceptible to a Blind SQL Injection vulnerability due to improper neutralization of special elements within SQL commands.\nThis security flaw allows an unauthenticated or authenticated attacker to perform Blind SQL Injection by manipulating crafted inputs processed by the plugin.\nSuccessful exploitation enables an attacker to infer sensitive information from the underlying database by observing the application's response behavior, as the vulnerability does not require direct output of query results.\nThe vulnerability affects WPLMS versions prior to 1.9.9.8.2.\nThe primary risk implications include unauthorized data exfiltration, database structure discovery, and potential compromise of site integrity if administrative credentials or session tokens are extracted via inference techniques.\nExploitation requires no specific privileges if the vulnerable endpoint is exposed to the public; however, the attacker must be able to craft malicious SQL payloads that the application processes without sanitization.",
  "technicalDetails": "The vulnerability is categorized as CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'). In the context of WPLMS, the plugin fails to sufficiently sanitize or parameterize user-supplied input before incorporating it into database queries.\nThe root cause lies in the application's handling of specific input parameters within the WPLMS codebase. By injecting SQL meta-characters and Boolean or time-based operators, an attacker can manipulate the query logic. Because this is a Blind SQL Injection vulnerability, the application does not return the direct results of the injected SQL queries to the user; instead, the attacker must rely on side-channel analysis.\nThe exploitation flow typically involves sending specially crafted HTTP requests to the vulnerable plugin component. The attacker utilizes Boolean-based inference—observing whether the application's response changes based on a true/false condition in the injected query—or time-based inference, where the attacker injects commands such as SLEEP() to measure server response latency. By iterating through database contents character-by-character, an attacker can extract data from the backend database, such as administrator hashes, configuration details, or user records.\nThe vulnerable component processes these inputs without utilizing prepared statements or robust input validation mechanisms. Consequently, the input is concatenated directly into the SQL string executed by the database engine. This creates a bridge between the attacker's request and the database, allowing for the execution of arbitrary SQL commands restricted only by the privileges of the database user account configured for the WordPress instance.\nThe vulnerability persists across all versions of WPLMS before 1.9.9.8.2. Since the plugin operates within the WordPress environment, this vulnerability is exposed over the network, typically via HTTP/HTTPS protocols, and can be triggered by any remote attacker capable of interacting with the plugin's exposed functional endpoints.\nPost-exploitation impact is severe, as it facilitates data leakage and provides an attacker with a foothold to conduct further reconnaissance, potentially leading to unauthorized access to the WordPress administrative dashboard or complete takeover of the site's data management capabilities."
}
CVE-2026-96327: Blind SQL Injection in WPLMS (CRITICAL Severity, CVSS: 9.3) | Sceawere