CVE-2015-10139 – WPLMS WordPress Privilege Escalation

CVE ID : CVE-2015-10139

Published : July 19, 2025, 12:15 p.m. | 1 hour, 25 minutes ago

Description : The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the ‘wp_ajax_import_data’ AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Share the Post:

Related Posts