
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability identified as CVE-2024-1128 affects Tutor LMS WordPress plugin versions up to 2.6.0. This security flaw was publicly disclosed on February 20, 2024, and involves an authenticated HTML injection vulnerability in the Q&A functionality that can be exploited by users with student-level access or higher (Wordfence Intel).
The vulnerability has been assigned a CVSS score of 5.4, categorizing it as a Medium severity issue (Wordfence Intel). The security flaw specifically relates to HTML injection capabilities in the Q&A feature of the Tutor LMS plugin.
When exploited, this vulnerability allows authenticated users with student-level access or higher to inject HTML code through the Q&A functionality, potentially leading to various security risks in the WordPress installation (Wordfence Intel).
The vulnerability requires authentication with at least student-level access to exploit, which somewhat limits its potential impact. However, given that student access is a common role in learning management systems, the attack surface remains significant (Wordfence Intel).
Website administrators running Tutor LMS are advised to update their installation to version 2.6.1 or later, which contains patches for this vulnerability (Wordfence Intel).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."