CVE-2024-43231: WordPress Tutor LMS plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43231?
The severity of CVE-2024-43231 is classified as high due to the potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2024-43231?
To fix CVE-2024-43231, users should update Themeum Tutor LMS or the WordPress Tutor LMS plugin to version 2.7.4 or later.
What platforms are affected by CVE-2024-43231?
CVE-2024-43231 affects Themeum Tutor LMS and the WordPress Tutor LMS plugin, specifically versions up to 2.7.3.
What is the impact of CVE-2024-43231?
The impact of CVE-2024-43231 includes the potential for attackers to inject malicious scripts that could execute in users' browsers.
Who is the vendor for CVE-2024-43231?
The vendor for CVE-2024-43231 is Themeum, which develops the Tutor LMS product.