← Vulnerability feed

Vulnerability record · CVE-2024-10470 · published 9 November 2024

CVE-2024-10470: Vibethemes wordpress learning management system path traversal vulnerability

Vibethemes · Wordpress Learning Management System

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.

9.8 CVSS 3.1 Critical EPSS 35% · top 1.6% CWE-22 · Path traversal
9.8CVSS 3.1 base score
35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-10470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-58668Vibethemes wordpress learning management system missing authorization vulnerabilityMissing Authorization vulnerability in VibeThemes WPLMS wplms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…EPSS 0.28%9.8CVE-2024-56043Vibethemes wordpress learning management system vulnerabilityIncorrect Privilege Assignment vulnerability in VibeThemes WPLMS wplms_plugin allows Privilege Escalation.This issue affects WPLMS: from n/a through …EPSS 0.63%9.8CVE-2024-56044Vibethemes wordpress learning management system authentication bypass via alternate path vulnerabilityAuthentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentication Bypass.This issue affec…EPSS 0.81%9.8CVE-2024-56042Vibethemes wordpress learning management system sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Inject…EPSS 0.70%9.8CVE-2024-56046Vibethemes wordpress learning management system unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a…EPSS 0.76%9.3CVE-2024-56045Vibethemes wordpress learning management system vulnerabilityPath Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.EPSS 0.68%8.8CVE-2024-56053Vibethemes wordpress learning management system sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Inject…EPSS 0.44%8.8CVE-2024-56054Vibethemes wordpress learning management system unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2024-10470), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.