Tutor LMS <= 3.4.0 - Authenticated (Subscriber+) HTML Injection

2025-04-07 00:00
Revan Arifio

Strategic Overview

Status
Patched in 3.4.1
Affected Version<= 3.4.0
CVSS4.3Medium
CVECVE-2025-32230
View all Tutor LMS – eLearning and online course solution vulnerabilities

Vulnerability Overview

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 3.4.0. This is due to the plugin not properly restricting HTML content from subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject HTML where they should not be authorized to.

Technical Analysis

REMEDIATION: Update to version 3.4.1, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C