QID 730907
Date Published: 2023-09-20
QID 730907: WordPress Plugin Tutor LMS Reflected Cross-Site Scripting (XSS) Vulnerability
Tutor LMS is a complete, feature-packed, and robust WordPress LMS plugin to easily create and sell courses online.
CVE-2023-0236: WordPress plugin Tutor LMS versions before 2.0.10 does not sanitize and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting vulnerability.
Affected Versions:
WordPress Tutor LMS Plugin versions prior to 2.0.10
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version by executing Cross-Site Scripting (XSS) POC.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary JavaScript code on the targeted users browser.
Solution
Customers are advised to upgrade to Tutor LMS version 2.0.10 or later to remediate this vulnerability.
Vendor References
- Tutor LMS Plugin Release Notes -
wordpress.org/plugins/tutor/#developers
CVEs related to QID 730907
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Tutor LMS Plugin Release Notes |
|