Extension WordPress

Vulnérabilités Tutor LMS – eLearning and online course solution, page 3

Cette page rassemble les failles publiées pour Tutor LMS – eLearning and online course solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.

73Vulnérabilités
2Critiques
73Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Tutor LMS – eLearning and online course solution

73 fiches

CVE-2024-4279 Moyenne · 6,5
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution <= 2.7.0 – Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course Deletion

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation…

Versions affectées

*-2.7.0

Correctif

2.7.1

Publication

15/05/2024

CVE-2024-3553 Moyenne · 6,5
Tutor LMS – eLearning and online course solution

Tutor LMS <= 2.6.2 – Missing Authorization to Unauthenticated Limited Options Update

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices function in all versions up to, and including, 2.6.2. This…

Versions affectées

*-2.6.2

Correctif

2.7.0

Publication

26/04/2024

CVE-2024-3994 Moyenne · 5,4
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution <= 2.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' Shortcode

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tutor_instructor_list' shortcode in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output…

Versions affectées

*-2.6.2

Correctif

2.7.0

Publication

24/04/2024

CVE-2024-1502 Moyenne · 5,4
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution <= 2.6.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. This…

Versions affectées

*-2.6.1

Correctif

2.6.2

Publication

12/03/2024

CVE-2024-1503 Moyenne · 4,3
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution <= 2.6.1 – Cross-Site Request Forgery to Plugin Deactivation and Data Erase

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the erase_tutor_data()…

Versions affectées

*-2.6.1

Correctif

2.6.2

Publication

12/03/2024

CVE-2024-1751 Élevée · 8,8
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution <= 2.6.1 – Authenticated (Subscriber+) SQL Injection

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied…

Versions affectées

*-2.6.1

Correctif

2.6.2

Publication

11/03/2024

CVE-2023-49829 Moyenne · 4,4
Tutor LMS – eLearning and online course solution

Tutor LMS <= 2.2.4 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.2.4

Correctif

2.3.0

Publication

05/12/2023

CVE-2023-4805 Moyenne · 6,4
Tutor LMS – eLearning and online course solution

Tutor LMS <= 2.2.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber access to…

Versions affectées

*-2.2.4

Correctif

2.3.0

Publication

25/09/2023

CVE-2022-2563 Moyenne · 5,5
Tutor LMS – eLearning and online course solution

Tutor LMS <= 2.0.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the topic name and lesson name parameters in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.0.9

Correctif

2.0.10

Publication

26/09/2022

Vulnérabilité Moyenne · 6,1
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution 2.0.0-2.0.8 – Reflected Cross-Site Scripting

The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions 2.0.0-2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…

Versions affectées

2.0.0-2.0.8

Correctif

2.0.9

Publication

22/08/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités