Tutor LMS——WordPress 的在线课程管理插件——在包括 4.0.5 及之前的所有版本中,通过 AJAX 操作存在远程代码执行(RCE)漏洞,但仅限于调用无参数的函数。该漏洞源于处理程序缺少权限验证,且未对传入 中 的数组键进行清理,导致攻击者可控的 POST 数据能够覆盖局部变量 。在最终使用的 模板中,变量 和 会被用于调用 。这使得未认证的攻击者可以在服务器端调用任意无参数的 PHP 函数,并通过 WordPress 核心函数 ,利用请求参数创建一个持久化的订阅者级别账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themeum | Tutor LMS – eLearning and online course solution | ≤ 4.0.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeum | Tutor LMS – eLearning and online course solution | 0 ~ 4.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet