CVE-2025-49925: WordPress WPLMS plugin <= 1.9.9.7 - Broken Access Control vulnerability
Published Oct 22, 2025
·Updated
Missing Authorization vulnerability in VibeThemes WPLMS wplmsplugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.7.
Affected Software
3 affected components
VibeThemes WPLMS<=1.9.9.7
WordPress WPLMS plugin<=1.9.9.7
VibeThemes Wordpress Learning Management System Wordpress<1.9.9.8
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 17, 58279
Event
via MITRE·05:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-49925?
The severity of CVE-2025-49925 is categorized as a missing authorization vulnerability allowing unauthorized access to functionality.
2
What versions are affected by CVE-2025-49925?
CVE-2025-49925 affects VibeThemes WPLMS versions up to and including 1.9.9.7.
3
How do I fix CVE-2025-49925?
To fix CVE-2025-49925, update VibeThemes WPLMS to the latest version that addresses this vulnerability.
4
What is the impact of CVE-2025-49925 on WPLMS users?
The impact of CVE-2025-49925 on WPLMS users includes potential unauthorized access to restricted functionalities.
5
Is CVE-2025-49925 a known vulnerability?
Yes, CVE-2025-49925 is a recognized vulnerability listed in the Common Vulnerabilities and Exposures database.