CVE-2024-1128

MEDIUM

Tutor LMS - WordPress <2.6.0 - Code Injection

Title source: llm
STIX 2.1

Description

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.6.0. This is due to insufficient sanitization of HTML input in the Q&A functionality. This makes it possible for authenticated attackers, with Student access and above, to inject arbitrary HTML onto a site, though it does not allow Cross-Site Scripting

Scores

CVSS v3 5.4
EPSS 0.0051
EPSS Percentile 39.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-79
Status published
Products (2)
themeum/Tutor LMS – eLearning and online course solution < 2.6.0
themeum/tutor_lms < 2.6.1
Published Feb 29, 2024
Tracked Since Feb 18, 2026