S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-0236 Scanner

CVE-2023-0236 scanner - XSS vulnerability in WordPress Tutor LMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-0236
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Tutor LMS
AFFECTED< 2.0.10SAFE ✓≥ 2.0.10
Updated Aug 22, 2026View on NVD →
Detail

WordPress Tutor LMS is an advanced, feature-rich Learning Management System (LMS) plugin designed for WordPress websites. It enables educators to create, manage, and sell online courses with ease. Utilized by educational institutions, professional trainers, and individual educators worldwide, Tutor LMS offers a powerful platform for delivering educational content online. With its intuitive course builder, quiz creator, and reporting features, it facilitates engaging learning experiences. The plugin supports a range of multimedia and interactive elements, making it a popular choice for online education.

The Cross-Site Scripting (XSS) vulnerability in WordPress Tutor LMS plugin before version 2.0.10 stems from the plugin’s failure to properly sanitize and escape user-supplied input in the reset_key and user_id parameters. This oversight allows attackers to inject malicious scripts into web pages, which are then executed in the context of the user's browser. Such scripts can steal cookies, hijack sessions, or redirect users to malicious websites, posing a significant security risk, especially when exploited against users with administrative privileges.

The XSS vulnerability is specifically present in the password reset functionality of the Tutor LMS plugin. By manipulating the reset_key and user_id parameters, attackers can embed malicious JavaScript code into the generated web page. The injected script is executed when an unsuspecting user views the compromised page, leading to potential security breaches such as session hijacking and data theft. The lack of proper input validation and output encoding in these parameters highlights a critical security oversight in the plugin's development.

Exploiting this vulnerability could lead to unauthorized access to sensitive information, compromise of user accounts, and control over the affected website. Attackers could potentially redirect users to phishing sites, modify content on the website, or perform actions on behalf of the user, including administrative actions if the targeted user is an administrator. This could severely impact the integrity and reputation of the website, leading to loss of trust among users and potential legal implications.

S4E's advanced scanning technology empowers website owners to detect and mitigate vulnerabilities like the XSS in WordPress Tutor LMS, ensuring their sites remain secure against potential threats. By becoming a member of our platform, you gain access to detailed vulnerability reports, expert guidance, and tools designed to enhance your website's security posture. Our service provides peace of mind by continuously monitoring for new vulnerabilities and helping you stay ahead of threats, making it an invaluable resource for maintaining a secure online presence.

 

References

Solution Advice
  1. Update the Tutor LMS plugin to version 2.0.10 or later immediately.
  2. Regularly update all WordPress plugins and themes to their latest versions to protect against known vulnerabilities.
  3. Implement content security policies (CSP) to mitigate the impact of any successful XSS attacks.
  4. Conduct regular security audits and scans to identify and address potential vulnerabilities.
  5. Educate users, especially administrators, on the importance of cautious link clicking and the potential risks of XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-0236 scanner - XSS vulnerability in WordPress Tutor LMS | S4E