Patchstack researchers have discovered 18 critical vulnerabilities in the WPLMS theme and its associated VibeBP plugin, widely used in WordPress-based learning management systems (LMS). These vulnerabilities expose websites to severe risks, including remote code execution (RCE), privilege escalation, and SQL injection attacks. WPLMS, utilized by educational institutions and e-learning platforms, integrates with WooCommerce for selling courses, making these flaws particularly dangerous for users. Key vulnerabilities in WPLMS include CVE-2024-56046 (CVSS 10.0), which allows unauthenticated attackers to upload malicious files, potentially enabling RCE. CVE-2024-56050 (CVSS 9.9) and CVE-2024-56052 (CVSS 9.9 enable low-privileged users (subscribers and students) to bypass file upload restrictions. Additionally, CVE-2024-56043 (CVSS 9.8) allows attackers to register as any role, including Administrator, without authentication, while CVE-2024-56042 (CVSS 9.3) and CVE-2024-56047 (CVSS 8.5) allow SQL injection attacks, leading to potential database compromises and data leaks. For VibeBP, vulnerabilities like CVE-2024-56040 (CVSS 9.8) allow attackers to register as privileged users without authentication, and CVE-2024-56039 (CVSS 9.3) exposes SQL injection risks due to insufficient input sanitization. CVE-2024-56041 (CVSS 8.5) allows authenticated low-privilege users to execute SQL injections and extract sensitive data. Users of WPLMS are urged to upgrade to version 1.9.9.5.3 or later, and VibeBP users should update to version 1.9.9.7.7 or newer. Patchstack also advises enforcing secure file uploads, SQL query sanitization, and role-based access controls as essential security measures. Vibe Themes worked closely with Patchstack to address and patch these vulnerabilities after being notified in March 2024.
IBM released security patches for over 100 vulnerabilities across various products. The biggest sufferers of these patches were Storage Defender, for which patches were issued for ...
Fieldtex Products, a U.S.-based provider of contract sewing and medical supply fulfillment, has reported a data breach following an attack attributed to a well-known ransomware ope...
The Pierce County Library System (PCLS) has announced a major data breach affecting more than 340,000 individuals, including library patrons, employees, former employees, and some ...