CVE-2020-8615
MEDIUM 6.5EPSS 8.8%
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N - CVSS v2.0
- 2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N - EPSS
- 8.83% chance of exploitation in the next 30 days, 95th percentile
- Nuclei
- medium · CWE-352
- Published
- 2020-02-04
- Updated
- 2024-08-04
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-…
- https://www.getastra.com/blog/911/plugin-exploit/cross-site-request-forgery-in-tutor-lms-…