Files
CVEs-PoC/2015/CVE-2015-10139.md
T
2025-09-29 21:09:30 +02:00

862 B

CVE-2015-10139

Description

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.

POC

Reference

No PoCs from references.

Github