WPLMS Learning Management System for WordPress, WordPress LMS

WPLMS Learning Management System for WordPress, WordPress LMS has 18 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2025; all 18 are fixed as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 10 high. 2024 was the busiest year with 15 disclosures.

The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 5 of the records (28%). Other recurring categories include Path Traversal, Missing Authorization.

Every one of the 18 issues recorded for WPLMS Learning Management System for WordPress, WordPress LMS has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, most of them (15) reported by Rafie Muhammad.

01234567891008.02.2015Today08.02.20158.8WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation CVSS 8.8 · 08.02.201505.07.20236.3WPLMS < 4.900 - Cross-Site Request Forgery CVSS 6.3 · 05.07.202308.11.20249.8WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion CVSS 9.8 · 08.11.202417.12.20248.8WPLMS <= 1.9.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update CVSS 8.8 · 17.12.20248.2WPLMS < 1.9.9.5 - Unauthenticated Arbitrary Directory Deletion CVSS 8.2 · 17.12.20249.8WPLMS <= 1.9.9 - Unauthenticated Privilege Escalation CVSS 9.8 · 17.12.20248.8WPLMS < 1.9.9.5.2 - Authenticated (Contributor+) Arbitrary File Upload CVSS 8.8 · 17.12.20248.8WPLMS < 1.9.9.5.2 - Authenticated (Instructor+) Arbitrary File Upload CVSS 8.8 · 17.12.20245.3WPLMS <= 1.9.9 - Missing Authorization to Unauthenticated User Token Generation CVSS 5.3 · 17.12.20247.1WPLMS < 1.9.9.5.2 - Authenticated (Subscriber+) Arbitrary File Deletion CVSS 7.1 · 17.12.20246.5WPLMS < 1.9.9.5.3 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 17.12.20247.1WPLMS < 1.9.9.5.2 - Authenticated (Contributor+) Arbitrary Directory Deletion CVSS 7.1 · 17.12.20248.8WPLMS < 1.9.9.5.3 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 17.12.20248.8WPLMS < 1.9.9.5 - Authenticated (Student+) Remote Code Execution CVSS 8.8 · 17.12.20249.8WPLMS <= 1.9.9 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 17.12.20248.8WPLMS < 1.9.9.5.2 - Authenticated (Student+) Arbitrary File Upload CVSS 8.8 · 17.12.20246.5WPLMS < 1.9.9.5.3 - Authenticated (Instructor+) SQL Injection CVSS 6.5 · 17.12.202422.09.20255.4WPLMS <= 4.970 - Missing Authorization CVSS 5.4 · 22.09.2025

Strategic Overview

Avg CVSSHigh
8.0/ 10
Patch Coverage100%
Open

0

Fixed

18

Get automatic notifications for all WPLMS Learning Management System for WordPress, WordPress LMS vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2024-56043

WPLMS <= 1.9.9 - Unauthenticated Privilege Escalation

Read the full analysis

Vulnerability Records

18 records
2025-09-22 00:00CVE-2025-58668
5.4
Medium
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56048
8.8
High
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56045
8.2
High
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56043
9.8
Critical
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56057
8.8
High
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56054
8.8
High
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56044
5.3
Medium
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56049
7.1
High
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56047
6.5
Medium
Rafie MuhammadYes
2024-12-17 00:00CVE-2024-56055
7.1
High
Rafie MuhammadYes
Showing 1–10 of 18 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C