CVE-2023-4805: Tutor LMS < 2.3.0 - Subscriber+ Stored Cross-Site Scripting
Published Oct 16, 2023
·Updated
The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
1 affected component
Themeum Tutor Lms Wordpress<2.3.0
Event History
Oct 16, 2023
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security flaw?
The vulnerability ID is CVE-2023-4805.
2
What is the severity rating of CVE-2023-4805?
The severity rating of CVE-2023-4805 is medium with a score of 5.4.
3
What is the affected software by CVE-2023-4805?
The affected software is the Tutor LMS WordPress plugin before version 2.3.0.
4
What can an attacker do with CVE-2023-4805?
An attacker can perform Stored Cross-Site Scripting attacks using this vulnerability.
5
Is there a fix available for CVE-2023-4805?
Yes, updating the Tutor LMS WordPress plugin to version 2.3.0 or higher fixes this vulnerability.