Tutor LMS 这款用于 WordPress 的 eLearning 和在线课程解决方案插件,由于输入净化不足和输出转义缺失,在所有版本(包括 4.0.8 及之前版本)中,通过 参数存在反射型跨站脚本攻击(Reflected Cross-Site Scripting, XSS)漏洞。这使得未经身份验证的攻击者能够诱导用户执行某些操作(例如点击某个链接),从而在会执行该操作的页面中注入任意 Web 脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeum | Tutor LMS – eLearning and online course solution | 0 ~ 4.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89333 | 6.5 MEDIUM | Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensi |
| CVE-2026-88944 | 4.3 MEDIUM | Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post D |
No comments yet