CVE-2020-8615
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
- Affected products
- Tutor Lms
- Themeum Tutor Lms
- < 1.5.3
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 8.8% (95th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2020-02-04
CVE-2020-8615 at NVD
5 known exploits for CVE-2020-8615
Proof-of-concept code and exploit modules indexed by Sploitus
Wordpress Tutor LMS 1.5.3 Plugin - Cross-Site Request Forgery (Add User) Vulnerability
Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
WordPress Tutor LMS 1.5.3 Cross Site Request Forgery
Tutor LMS < 1.5.3 - Cross-Site Request Forgery (CSRF)