CVE-2015-10139 Information

Description

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the ‘wp_ajax_import_data’ AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://packetstormsecurity.com/files/130291/ https://themeforest.net/item/wplms-learning-management-system/6780226 https://twitter.com/wpscan/status/564874637679820800?lang=ca https://wpscan.com/vulnerability/7785 https://www.rapid7.com/db/modules/auxiliary/admin/http/wp_wplms_privilege_escalation/ https://www.wordfence.com/threat-intel/vulnerabilities/id/6e0e8f5f-8216-4276-a810-860f9b52c447?source=cve

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

CNNVD-202507-2506 (Published: 2025-07-19)

Share on: