Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons allows Stored XSS.This issue affects Tutor LMS Elementor Addons: from n/a through <= 3.0.1.
Published: 2025-12-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that arises from improper sanitization of user input during web page generation within the Themeum Tutor LMS Elementor Addons plugin. Attackers can inject and store malicious scripts that will run in the browsers of anyone who views the affected content, potentially enabling session hijacking, cookie theft, defacement, and phishing attacks. This weakness is a classic input validation failure (CWE‑79) and can compromise the confidentiality, integrity, and availability of the site’s user base.

Affected Systems

The flaw impacts WordPress sites that use the Tutor LMS Elementor Addons plugin at versions up to 3.0.1. Any site deploying these plugin versions is susceptible; versions beyond 3.0.1 are not affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk, but the EPSS score of less than 1 % suggests current exploitation attempts are unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply crafted input that the plugin accepts and later triggers on page load; no privilege escalation is indicated. The most practical exploitation path is through content editing interfaces that the plugin provides, allowing an attacker with content creation privileges to insert malicious scripts.

Generated by OpenCVE AI on April 29, 2026 at 12:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tutor LMS Elementor Addons plugin to a version newer than 3.0.1 where the stored XSS issue has been fixed.
  • If an immediate upgrade is not possible, deactivate or remove the plugin entirely, or disable the plugin’s content editing features that accept untrusted input.
  • Configure a web application firewall or server‑side input filtering to encode or strip script tags from data stored by the plugin as a temporary safeguard.

Generated by OpenCVE AI on April 29, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 02 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum tutor Lms Elementor Addons
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum tutor Lms Elementor Addons
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons allows Stored XSS.This issue affects Tutor LMS Elementor Addons: from n/a through <= 3.0.1.
Title WordPress Tutor LMS Elementor Addons plugin <= 3.0.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Themeum Tutor Lms Elementor Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:34:46.513Z

Reserved: 2025-10-24T14:26:26.918Z

Link: CVE-2025-63042

cve-icon Vulnrichment

Updated: 2025-12-09T17:08:01.249Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:09.477

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-63042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:30:10Z

Weaknesses