CVE-2025-32230: WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS tutor.This issue affects Tutor LMS: from n/a through <= 3.4.0.
Other sources
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32230?
CVE-2025-32230 is classified as a medium-severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2025-32230?
To fix CVE-2025-32230, upgrade Themeum Tutor LMS to version 3.4.1 or later.
What versions of Tutor LMS are affected by CVE-2025-32230?
CVE-2025-32230 affects Tutor LMS versions up to and including 3.4.0.
What type of vulnerability is CVE-2025-32230?
CVE-2025-32230 is an improper neutralization vulnerability that allows script-related HTML tags to be executed in web pages.
Can CVE-2025-32230 impact user data?
Yes, CVE-2025-32230 can potentially impact user data by enabling attackers to execute malicious scripts in the context of a logged-in user.