CVE-2023-4805
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Oct 16, 2023
Updated: Nov 7, 2023
CWE ID 295
Summary
CVE-2023-4805 is a vulnerability affecting the Tutor LMS WordPress plugin before version 2.3.0. This issue permits users, including subscribers, to execute Stored Cross-Site Scripting attacks. Despite the unfiltered_html capability being disallowed, particularly in multisite setups, the plugin fails to sanitize and escape certain settings. This flaw can lead to the injection of malicious scripts into web pages, potentially compromising user data or taking control of affected sites.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- LocalStack
Affected Vendors
- Local Stack