CVE-2021-25017: Tutor LMS < 1.9.12 - Reflected Cross-Site Scripting
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-25017?
CVE-2021-25017 is a vulnerability in the Tutor LMS WordPress plugin before version 1.9.12 that allows for a Reflected Cross-Site Scripting attack.
How severe is CVE-2021-25017?
CVE-2021-25017 has a severity rating of 6.1, which is considered medium.
Which version of the Tutor LMS WordPress plugin is affected by CVE-2021-25017?
The Tutor LMS WordPress plugin version up to exclusive 1.9.12 is affected by CVE-2021-25017.
How can I fix CVE-2021-25017?
To fix CVE-2021-25017, users should update their Tutor LMS WordPress plugin to version 1.9.12 or above.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-25017?
The Common Weakness Enumeration (CWE) ID for CVE-2021-25017 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').