Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS tutor.This issue affects Tutor LMS: from n/a through <= 3.4.0.
Published: 2025-04-10
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of script‑related HTML tags allows an attacker to inject arbitrary HTML or JavaScript into pages generated by the Tutor LMS plugin. This basic XSS flaw is triggered when user‑controlled content is rendered without proper escaping, enabling malicious code to run in the victim’s browser. The vulnerability is classified as CWE‑80, highlighting that the plugin fails to encode or sanitize output before displaying it.

Affected Systems

Version identifiers affected are all releases of the Tutor LMS WordPress plugin up to and including 3.4.0, including the current 3.4.0 version. The plugin is distributed by Themeum under the name Tutor LMS. Because the vulnerability exists in all earlier releases, any site still running version 3.4.0 or older must be considered vulnerable until patched.

Risk and Exploitability

The score listed in CVSS is 4.3, indicating medium severity, and the EPSS score is less than 1 %, implying a very low likelihood of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote web‑based injection, whereby an attacker submits malicious content that the plugin later serves to visitors. Local privileges or administrative access are not required according to the description, so the flaw can affect any user who can create or edit content within Tutor LMS.

Generated by OpenCVE AI on April 30, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tutor LMS to the latest available version (any release newer than 3.4.0).
  • If immediate upgrading is not possible, ensure that any user‑provided data rendered by the plugin is properly escaped or filtered; consider using a content sanitization library.
  • Enable a strictly defined Content‑Security‑Policy that blocks inline scripts and restricts script sources to trusted domains.

Generated by OpenCVE AI on April 30, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10469 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0. Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS tutor.This issue affects Tutor LMS: from n/a through <= 3.4.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Thu, 10 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0.
Title WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerability
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Themeum Tutor Lms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:19.672Z

Reserved: 2025-04-04T10:01:50.054Z

Link: CVE-2025-32230

cve-icon Vulnrichment

Updated: 2025-04-10T18:58:42.994Z

cve-icon NVD

Status : Deferred

Published: 2025-04-10T08:15:19.603

Modified: 2026-04-23T15:28:47.830

Link: CVE-2025-32230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:30:03Z

Weaknesses