216.73.216.6

CVE-2015-10139

· Published 19/07/2025 12:15 · Modified 19/07/2025 12:15

Labels: CVE-2015-10139 2025-07-19CVE-2015-10139CWE-269[email protected]

Essential information

Published
19/07/2025 12:15
Modified
19/07/2025 12:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / wplms theme cpe:2.3:a:wordpress:wplms_theme:1.5.2-1.8.4.1:*:*:*:*:wordpress:*:*

References