Unknown Tutor Lms vulnerabilities
3 known vulnerabilities affecting unknown/tutor_lms.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-4805MEDIUMCVSS 5.4fixed in 2.3.02023-10-16
CVE-2023-4805 [MEDIUM] CWE-79 CVE-2023-4805: The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which
The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2023-3133HIGHCVSS 7.5fixed in 2.2.12023-07-04
CVE-2023-3133 [HIGH] CWE-639 CVE-2023-3133: The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST A
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
cvelistv5nvd
CVE-2023-0236MEDIUMCVSS 6.1PoCfixed in 2.0.102023-02-06
CVE-2023-0236 [MEDIUM] CWE-79 CVE-2023-0236: The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
cvelistv5nvd