{"api_version":"1","generated_at":"2026-07-24T03:02:49+00:00","cve":"CVE-2020-8615","urls":{"html":"https://cve.report/CVE-2020-8615","api":"https://cve.report/api/cve/CVE-2020-8615.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-8615","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-8615"},"summary":{"title":"CVE-2020-8615","description":"A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-02-04 20:15:00","updated_at":"2022-01-01 20:03:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"https://www.jinsonvarghese.com/cross-site-request-forgery-in-tutor-lms/","name":"https://www.jinsonvarghese.com/cross-site-request-forgery-in-tutor-lms/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Cross-Site Request Forgery in Tutor LMS Plugin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.themeum.com/tutor-lms-updated-v1-5-3/","name":"https://www.themeum.com/tutor-lms-updated-v1-5-3/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Update Your Tutor LMS: CSRF Vulnerability Patched in Latest Version - Themeum","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.getastra.com/blog/911/plugin-exploit/cross-site-request-forgery-in-tutor-lms-plugin/","name":"https://www.getastra.com/blog/911/plugin-exploit/cross-site-request-forgery-in-tutor-lms-plugin/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Ecommerce Security: Importance, Issues & Protection Measures","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.html","name":"http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.html","refsource":"MISC","tags":[],"title":"WordPress Tutor LMS 1.5.3 Cross Site Request Forgery ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://wpvulndb.com/vulnerabilities/10058","name":"https://wpvulndb.com/vulnerabilities/10058","refsource":"MISC","tags":["Third Party Advisory"],"title":"Tutor LMS < 1.5.3 - Cross-Site Request Forgery (CSRF) Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-8615","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8615","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"8615","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"themeum","cpe5":"tutor_lms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"8615","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"themeum","cpe5":"tutor_lms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-8615","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://wpvulndb.com/vulnerabilities/10058","refsource":"MISC","name":"https://wpvulndb.com/vulnerabilities/10058"},{"url":"https://www.themeum.com/tutor-lms-updated-v1-5-3/","refsource":"MISC","name":"https://www.themeum.com/tutor-lms-updated-v1-5-3/"},{"url":"https://www.getastra.com/blog/911/plugin-exploit/cross-site-request-forgery-in-tutor-lms-plugin/","refsource":"MISC","name":"https://www.getastra.com/blog/911/plugin-exploit/cross-site-request-forgery-in-tutor-lms-plugin/"},{"url":"https://www.jinsonvarghese.com/cross-site-request-forgery-in-tutor-lms/","refsource":"MISC","name":"https://www.jinsonvarghese.com/cross-site-request-forgery-in-tutor-lms/"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.html","url":"http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.html"}]}},"nvd":{"publishedDate":"2020-02-04 20:15:00","lastModifiedDate":"2022-01-01 20:03:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":2.6},"severity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"1.5.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"8615","Ordinal":"168955","Title":"CVE-2020-8615","CVE":"CVE-2020-8615","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"8615","Ordinal":"1","NoteData":"A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).","Type":"Description","Title":null},{"CveYear":"2020","CveId":"8615","Ordinal":"2","NoteData":"2020-02-04","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"8615","Ordinal":"3","NoteData":"2020-03-02","Type":"Other","Title":"Modified"}]}}}