CVE-2023-25800: WordPress Tutor LMS plugin <= 2.2.0 - Multiple Student+ SQL Injection vulnerability
Published Nov 3, 2023
·Updated
A vulnerability in Themeum Tutor LMS tutor.This issue affects Tutor LMS: from n/a through <= 2.2.0.
Affected Software
1 affected component
Themeum Tutor Lms Wordpress<=2.2.0
Remediation
Information
Update to 2.2.1 or a higher version.
Event History
Nov 3, 2023
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-25800?
CVE-2023-25800 is a vulnerability in the WordPress Tutor LMS Plugin <= 2.2.0 that allows SQL Injection.
2
How does the CVE-2023-25800 vulnerability work?
The CVE-2023-25800 vulnerability in the WordPress Tutor LMS Plugin allows an attacker to inject malicious SQL commands into the application's database, potentially gaining unauthorized access or manipulating data.
3
What is the severity of CVE-2023-25800?
CVE-2023-25800 has a severity rating of 8.8 (high).
4
What software versions are affected by CVE-2023-25800?
The CVE-2023-25800 vulnerability affects Themeum Tutor LMS versions up to and including 2.2.0.
5
Is there a patch or fix available for CVE-2023-25800?
Yes, a patch for CVE-2023-25800 is available. Please refer to the reference link for more information.