Vibethemes develops a compact portfolio of WordPress plugins and extensions for learning management and social connectivity, a niche product line that punches above its typical exposure profile. Vulnerabilities affecting the vendor skew strongly toward critical severity and concentrate across a cluster of recurring weakness classes endemic to WordPress plugin development: unrestricted file uploads, cross-site scripting, SQL injection, missing authorization checks, and path traversal—all of which reflect insufficient input validation and access control in web application plugins. The exposure spans products including the WordPress Learning Management System, vSlider, and BP Social Connect, each presenting a direct attack surface to site administrators and authenticated users. Defenders should treat updates for this vendor's plugins as a patching priority, particularly in sites where plugin code runs in trusted contexts; live exploitation activity and severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vibethemes over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10470CRITICAL The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and | Nov 9, 2024 | 9.8 | 41 | NO | NO |
CVE-2015-10139HIGH The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated | Jul 19, 2025 | 8.8 | 38 | NO | YES |
CVE-2025-58668CRITICAL Missing Authorization vulnerability in VibeThemes WPLMS wplms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLMS : from n/a through < | Sep 22, 2025 | 9.8 | 33 | NO | NO |
CVE-2023-2704CRITICAL The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being | May 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-56045CRITICAL Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5. | Dec 31, 2024 | 9.3 | 29 | NO | NO |
CVE-2024-56044CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentication Bypass.This issue affects WPLMS: from n/a through <= 1 | Dec 31, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-56046CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through | Dec 31, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-49925HIGH Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1 | Oct 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-56043CRITICAL Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS wplms_plugin allows Privilege Escalation.This issue affects WPLMS: from n/a through <= 1.9.9. | Dec 31, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-56042CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: f | Dec 31, 2024 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vibethemes.
Media articles that mention a CVE ID that affects a product developed by Vibethemes — matched by CVE ID, not by vendor name.