CVE-2025-53420: WordPress WPLMS plugin <= 1.9.9.8 - Cross Site Scripting (XSS) vulnerability
Published Oct 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplmsplugin allows Reflected XSS.This issue affects WPLMS: from n/a through <= 1.9.9.8.
Affected Software
2 affected components
VibeThemes WPLMS<=1.9.9.8
VibeThemes Wordpress Learning Management System Wordpress<=1.9.9.8
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53420?
CVE-2025-53420 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-53420?
To remediate CVE-2025-53420, upgrade VibeThemes WPLMS to version 1.9.9.9 or later.
3
What versions are affected by CVE-2025-53420?
CVE-2025-53420 affects VibeThemes WPLMS versions up to and including 1.9.9.8.
4
What type of vulnerability is CVE-2025-53420?
CVE-2025-53420 is an Improper Neutralization of Input During Web Page Generation vulnerability, resulting in reflected XSS.
5
How can CVE-2025-53420 be exploited?
CVE-2025-53420 can be exploited by injecting malicious scripts into web pages, leading to compromised user sessions and sensitive information disclosure.