vciy

CVEs we hold for Vibethemes

Records whose assigning authority named Vibethemes as the affected vendor. Newest identifiers first, capped at 200.

CVE-2025-69097WordPress WPLMS plugin <= 1.9.9.5.4 - Arbitrary File Deletion vulnerabilityVibeThemes WPLMS
CVE-2025-63035WordPress WPLMS plugin <= 1.9.9.5.4 - Cross Site Scripting (XSS) vulnerabilityVibeThemes WPLMS
CVE-2025-58668WordPress WPLMS theme <= 4.970 - Broken Access Control vulnerabilityVibeThemes WPLMS
CVE-2025-53420WordPress WPLMS plugin <= 1.9.9.8 - Cross Site Scripting (XSS) vulnerabilityVibeThemes WPLMS
CVE-2025-49925WordPress WPLMS plugin <= 1.9.9.7 - Broken Access Control vulnerabilityVibeThemes WPLMS
CVE-2025-32493WordPress BP Social Connect plugin <= 1.6.2 - Cross Site Scripting (XSS) VulnerabilityVibeThemes BP Social Connect
CVE-2024-56057WordPress WPLMS plugin < 1.9.9.5.2 - Arbitrary File Upload vulnerabilityVibeThemes WPLMS
CVE-2024-56055WordPress WPLMS plugin < 1.9.9.5.2 - Arbitrary Directory Deletion vulnerabilityVibeThemes WPLMS
CVE-2024-56054WordPress WPLMS plugin < 1.9.9.5.2 - Instructor+ Arbitrary File Upload vulnerabilityVibeThemes WPLMS
CVE-2024-56053WordPress WPLMS plugin < 1.9.9.5.3 - Instructor+ SQL Injection vulnerabilityVibeThemes WPLMS
CVE-2024-56052WordPress WPLMS plugin < 1.9.9.5.2 - Student+ Arbitrary File Upload vulnerabilityVibeThemes WPLMS
CVE-2024-56051WordPress WPLMS plugin < 1.9.9.5 - Student+ Remote Code Execution (RCE) vulnerabilityVibeThemes WPLMS
CVE-2024-56050WordPress WPLMS plugin < 1.9.9.5.3 - Subscriber+ Arbitrary File Upload vulnerabilityVibeThemes WPLMS
CVE-2024-56049WordPress WPLMS plugin < 1.9.9.5.2 - Subscriber+ Arbitrary File Deletion vulnerabilityVibeThemes WPLMS
CVE-2024-56048WordPress WPLMS plugin <= 1.9.9 - Arbitrary Option Update to Privilege Escalation vulnerabilityVibeThemes WPLMS
CVE-2024-56047WordPress WPLMS plugin < 1.9.9.5.3 - Subscriber+ SQL Injection vulnerabilityVibeThemes WPLMS
CVE-2024-56046WordPress WPLMS plugin <= 1.9.9 - Unauthenticated Arbitrary File Upload vulnerabilityVibeThemes WPLMS
CVE-2024-56045WordPress WPLMS plugin < 1.9.9.5 - Unauthenticated Arbitrary Directory Deletion vulnerabilityVibeThemes WPLMS
CVE-2024-56044WordPress WPLMS plugin <= 1.9.9 - Unauthenticated Arbitrary User Token Generation vulnerabilityVibeThemes WPLMS
CVE-2024-56043WordPress WPLMS plugin <= 1.9.9 - Unauthenticated Privilege Escalation vulnerabilityVibeThemes WPLMS
CVE-2024-56042WordPress WPLMS plugin < 1.9.9.5.3 - Unauthenticated SQL Injection vulnerabilityVibeThemes WPLMS
CVE-2024-56041WordPress VibeBP plugin < 1.9.9.5.1 - SQL Injection vulnerabilityVibeThemes VibeBP
CVE-2024-56040WordPress VibeBP plugin <= 1.9.9.4.1 - Unauthenticated Privilege Escalation vulnerabilityVibeThemes VibeBP
CVE-2024-56039WordPress VibeBP plugin < 1.9.9.7.7 - Unauthenticated SQL Injection vulnerabilityVibeThemes VibeBP
CVE-2024-10470WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and DeletionVibeThemes WPLMS Learning Management System for WordPress…
CVE-2023-36690WordPress WPLMS Theme < 4.900 is vulnerable to Cross Site Request Forgery (CSRF)VibeThemes WPLMS
CVE-2023-2704BP Social Connect <= 1.5 - Authentication Bypassvibethemes BP Social Connect
CVE-2015-10139WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege EscalationVibeThemes WPLMS Learning Management System for WordPress…

28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.