CVE-2015-10139: WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation
Published Jul 19, 2025
·Updated
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wpajaximportdata' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
Affected Software
2 affected components
WPLMS WPLMS>=1.5.2<=1.8.4.1
WordPress Learning Management System<=1.8.4.1
Event History
Jul 19, 2025
CVE Published
via MITRE·11:23 AM
Data Sourced
via MITRE·11:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-10139?
CVE-2015-10139 is considered a medium severity vulnerability due to its potential for privilege escalation.
2
What versions are affected by CVE-2015-10139?
CVE-2015-10139 affects WPLMS versions from 1.5.2 to 1.8.4.1.
3
How do I fix CVE-2015-10139?
To fix CVE-2015-10139, you should update WPLMS to version 1.8.4.2 or later.
4
Can CVE-2015-10139 allow creation of new admin accounts?
Yes, CVE-2015-10139 allows authenticated attackers to create new admin accounts.
5
What type of vulnerability is CVE-2015-10139?
CVE-2015-10139 is classified as a privilege escalation vulnerability.