External risk intelligence

WPLMS Blind SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96327

This vulnerability exists in a WordPress plugin. WordPress sites and their associated plugins are commonly deployed as public-facing web applications, making the functionality exposed by this plugin reachable from the internet by design.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability, an SQL injection flaw in the WPLMS plugin for WordPress, could allow unauthorized access to data or system manipulation if exploited. The primary concern is to confirm if this specific plugin is in use and its presence within the organization's technology environment.

  • Allows data access via malicious SQL commands.
  • Critical for understanding potential data exposure.
  • Confirm usage to assess business risk.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted data to the WPLMS plugin through its network interface. The plugin's improper handling of SQL commands allows for the injection of malicious SQL code, which can lead to unauthorized data access or manipulation.

  • Network access required.
  • Vulnerable SQL command handling.
  • Leads to blind SQL injection.

Live Threat

Current exploitation, exposure, and threat context

A SQL injection vulnerability in the WPLMS plugin could allow an unauthenticated attacker to retrieve sensitive information from the database. This could occur when the plugin improperly processes special elements within an SQL command, leading to unintended database queries. The attacker could potentially access and exfiltrate data stored in the database when supported by the advisory.

  • Sensitive database information.
  • Through specially crafted SQL commands.
  • Unauthorized data retrieval.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders and system owners should coordinate with application owners and potentially infrastructure or platform teams to address this SQL injection vulnerability in the WPLMS plugin. The first practical step is to identify all instances of the WPLMS plugin, confirm their exposure and criticality, and then assign ownership for remediation planning based on the risk assessment.

  • Application owners should manage remediation.
  • Verify WPLMS plugin exposure and impact.
  • Plan targeted updates or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WPLMS plugin?

WPLMS is a Learning Management System (LMS) plugin designed for WordPress. It adds features for creating and managing online courses, student tracking, and educational content delivery, typically used by academic institutions or businesses to host training programs directly on their websites.

What does SQL injection mean for CVE-2026-96327?

This vulnerability is classified as Improper Neutralization of Special Elements used in an SQL Command, or CWE-89. It means the software does not properly sanitize user-provided input before using it in database queries. An attacker can supply malicious SQL code, tricking the database into performing unauthorized actions or revealing information it should keep private.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted input to the WPLMS plugin over a network. The flaw specifically allows for Blind SQL Injection, where the attacker may not see direct error messages but can infer database content by observing how the application responds to various manipulated queries.

Is my site at risk from this vulnerability?

According to Halo Surface Signal, this vulnerability is considered likely to be reachable because it exists in a WordPress plugin. WordPress plugins are often designed to be public-facing to provide functionality to users, meaning any instance of the affected software is potentially accessible from the internet.

When should I take action for this CVE?

You should act immediately by locating all installations of the WPLMS plugin within your environment. Once identified, consult your development or maintenance team to confirm your version and plan for the necessary updates provided by the vendor to remediate the vulnerability.

References