PT-2026-4167 · WordPress · Wplms

CVE-2025-69097

·

Publicado

2026-01-22

·

Atualizado

2026-01-22

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions VibeThemes WPLMS versions through 1.9.9.5.4
Description The WPLMS plugin contains a flaw related to improper limitation of a pathname to a restricted directory, specifically a Path Traversal issue. This allows unauthorized access to files and directories.
Recommendations Update WPLMS to a version newer than 1.9.9.5.4

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69097

Produtos afetados

Wplms