First published: Tue Feb 04 2020(Updated: )
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Themeum Tutor Lms | <1.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8615 is a CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress, which allows an attacker to approve themselves as an instructor and perform other malicious actions.
The Tutor LMS plugin before version 1.5.3 for WordPress is affected by CVE-2020-8615.
CVE-2020-8615 has a severity rating of 6.5, which is considered medium.
To fix CVE-2020-8615, you should update the Tutor LMS plugin to version 1.5.3 or later.
You can find more information about CVE-2020-8615 at the following references: [1] http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.html [2] https://wpvulndb.com/vulnerabilities/10058 [3] https://www.getastra.com/blog/911/plugin-exploit/cross-site-request-forgery-in-tutor-lms-plugin/