Page 5 of 21 results (0.006 seconds)

CVSS: 8.8EPSS: 1%CPEs: 1EXPL: 2

A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors). Una vulnerabilidad de tipo CSRF en el plugin Tutor LMS versiones anteriores a 1.5.3 para WordPress, puede resultar en que un atacante se apruebe como instructor y lleve a cabo otras acciones maliciosas (tales como bloquear instructores legítimos). WordPress Tutor LMS plugin version 1.5.3 suffers from a cross site request forgery vulnerability. • https://www.exploit-db.com/exploits/48151 http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.html https://wpvulndb.com/vulnerabilities/10058 https://www.getastra.com/blog/911/plugin-exploit/cross-site-request-forgery-in-tutor-lms-plugin https://www.jinsonvarghese.com/cross-site-request-forgery-in-tutor-lms https://www.themeum.com/tutor-lms-updated-v1-5-3 • CWE-352: Cross-Site Request Forgery (CSRF) •