PT-2023-6549 · WordPress · Tutor Lms

So Sakaguchi

·

Published

2023-01-12

·

Updated

2025-03-25

·

CVE-2023-0236

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS WordPress plugin versions prior to 2.0.10
Description The issue is related to the lack of protection of the SQL query structure in the Tutor LMS plugin for WordPress, potentially allowing a remote attacker to execute arbitrary code. Additionally, the plugin does not properly sanitise and escape certain parameters, such as reset key and user id, before outputting them, leading to Reflected Cross-Site Scripting. This could be exploited against high-privilege users, including administrators.
Recommendations For versions prior to 2.0.10, update to version 2.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the reset key and user id parameters to minimize the risk of exploitation. Avoid using these parameters in sensitive operations until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07311
CVE-2023-0236

Affected Products

Tutor Lms