CVE-2015-10139 describes a high-severity privilege escalation vulnerability affecting versions 1.5.2 to 1.8.4.1 of the WPLMS WordPress theme. This flaw, exploitable via the 'wp_ajax_import_data' AJAX action, allows authenticated attackers to modify restricted settings and potentially create new administrative accounts. With a CVSS score of 8.8 (High) and a FAUCET Risk Score of 99/100, the vulnerability presents a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, a Metasploit module exists for exploitation, and the CVE has garnered substantial community discussion, indicating awareness and potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.5.2, < 1.8.9CPE matchmatch criteria | cpe:2.3:a:vibethemes:wordpress_learning_management_system_:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.