CRITICAL 9.3 CVE-2026-96327 Published 9 Oct 2026

WPLMS WordPress Plugin Blind SQL Injection Vulnerability

Worried this affects your website?

A vulnerability in VibeThemes WPLMS has been disclosed as an SQL Injection flaw. The wplms_plugin component improperly neutralizes special elements used in an SQL command, allowing blind SQL injection.

The issue affects WPLMS versions from n/a before 1.9.9.8.2.

Reference: CVE-2026-96327 on NVD

← Back to Security News