Impact
This vulnerability, identified as a Reflected Cross‑Site Scripting flaw, allows an unauthenticated attacker to inject arbitrary scripts via the 'search' and 'back_url' parameters. Because the plugin fails to properly sanitise or escape these inputs, a malicious URL can be crafted that, when clicked by a victim, causes the browser to execute injected JavaScript. The resulting impact is credential theft or a session hijack in the victim's context, compromising confidentiality and integrity on the affected site.
Affected Systems
The issue covers the Tutor LMS eLearning plugin for WordPress versions up to and including 4.0.8. The plugin is developed and distributed by themeum. Clients running Tutor LMS 4.0.8 or earlier are therefore exposed.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score is not reported. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation reports yet. However, because the attack requires only a crafted link and does not need authentication, attackers can embed the payload in emails or social media posts to persuade users to click. Consequently, the potential for damage remains high until the plugin is upgraded.
OpenCVE Enrichment