Vulnerability Bulletins

Several Vulnerabilities Patched in Tutor LMS Plugin


System information

   
Affected software Wordpress

Description

On December 15, 2020, our Threat Intelligence team responsibly disclosed several vulnerabilities in Tutor LMS, a WordPress plugin installed on over 20,000 sites. The first five flaws made it possible for authenticated attackers to inject and execute arbitrary SQL statements on WordPress sites. This made it possible for attackers to obtain information stored in a […]

More info:

https://www.wordfence.com/blog/2021/03/several-vulnerabilities-patched-in-tutor-lms-plugin/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2021-03-19
Ministerio de Defensa
CNI
CCN
CCN-CERT