CRITICAL
9.3 CVE-2026-96327 Published 9 Oct 2026
WPLMS WordPress Plugin Blind SQL Injection Vulnerability
Worried this affects your website?
A vulnerability in VibeThemes WPLMS has been disclosed as an SQL Injection flaw. The wplms_plugin component improperly neutralizes special elements used in an SQL command, allowing blind SQL injection.
The issue affects WPLMS versions from n/a before 1.9.9.8.2.
Reference: CVE-2026-96327 on NVD
← Back to Security News