Themeum Tutor LMS
cpe:2.3:a:themeum:tutor_lms:*:*:*:*:wordpress:*:*
- <= 3.4.0
A cross-site scripting (XSS) vulnerability has been identified in the Themeum Tutor LMS WordPress plugin, specifically in versions through 3.4.0. This vulnerability arises from improper handling of script-related HTML tags, allowing for basic XSS attacks.
Exploitation of this vulnerability allows for content injection, which could be used to insert malicious scripts or phishing pages into the affected WordPress site.
Users of the Themeum Tutor LMS WordPress plugin should update to version 3.4.1 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.