Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vibethemes

First CVE: May 3, 2023Active for: 3 yearsTotal CVEs: 26
57.7
VTI Score
TOP TARGET

Vibethemes develops a compact portfolio of WordPress plugins and extensions for learning management and social connectivity, a niche product line that punches above its typical exposure profile. Vulnerabilities affecting the vendor skew strongly toward critical severity and concentrate across a cluster of recurring weakness classes endemic to WordPress plugin development: unrestricted file uploads, cross-site scripting, SQL injection, missing authorization checks, and path traversal—all of which reflect insufficient input validation and access control in web application plugins. The exposure spans products including the WordPress Learning Management System, vSlider, and BP Social Connect, each presenting a direct attack surface to site administrators and authenticated users. Defenders should treat updates for this vendor's plugins as a patching priority, particularly in sites where plugin code runs in trusted contexts; live exploitation activity and severity breakdowns are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vibethemes over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2023
3 years ago
Most Recent CVE
Dec 9, 2025
228 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-10470CRITICAL
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and
Nov 9, 20249.841NONO
CVE-2015-10139HIGH
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated
Jul 19, 20258.838NOYES
CVE-2025-58668CRITICAL
Missing Authorization vulnerability in VibeThemes WPLMS wplms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLMS : from n/a through <
Sep 22, 20259.833NONO
CVE-2023-2704CRITICAL
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being
May 19, 20239.830NONO
CVE-2024-56045CRITICAL
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
Dec 31, 20249.329NONO
CVE-2024-56044CRITICAL
Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentication Bypass.This issue affects WPLMS: from n/a through <= 1
Dec 31, 20249.826NONO
CVE-2024-56046CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through
Dec 31, 20249.826NONO
CVE-2025-49925HIGH
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1
Oct 22, 20257.525NONO
CVE-2024-56043CRITICAL
Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS wplms_plugin allows Privilege Escalation.This issue affects WPLMS: from n/a through <= 1.9.9.
Dec 31, 20249.825NONO
CVE-2024-56042CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: f
Dec 31, 20249.825NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
12%
58%
31%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (76.9%)
Unknown0 (0.0%)
Required6 (23.1%)
Privileges Required
Low12 (46.2%)
High2 (7.7%)
None12 (46.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vibethemes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vibethemes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vibethemes's Products

View all 2 CNAs →

Top CWEs