First published: Mon Oct 16 2023(Updated: )
The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeum Tutor LMS | <2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4805.
The severity rating of CVE-2023-4805 is medium with a score of 5.4.
The affected software is the Tutor LMS WordPress plugin before version 2.3.0.
An attacker can perform Stored Cross-Site Scripting attacks using this vulnerability.
Yes, updating the Tutor LMS WordPress plugin to version 2.3.0 or higher fixes this vulnerability.