Input validation vulnerability in Tutor LMS – eLearning and online course solution 2.2.4

The Tutor LMS plugin for WordPress, which is a solution for creating online courses, is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack can be done by people who have administrator access and is possible in all versions of the plugin up to version 2.2.4. It happens when the plugin does not properly sanitize or escape user input. The attacker can then inject web scripts into pages that will execute when a user visits the page. This vulnerability only affects multi-site installations and installations where the option “unfiltered_html” has been disabled.

Detected in:

Tutor LMS – eLearning and online course solution fixed vulnerable versions: >= * <= 2.2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.