Vulnerabilities > Themeum > Tutor LMS Elementor Addons
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-12-09 | CVE-2024-53816 | Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons.This issue affects Tutor LMS Elementor Addons: from n/a through 2.1.5. | 8.8 |
2024-11-15 | CVE-2024-10897 | Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() function in all versions up to, and including, 2.1.5. | 4.3 |
2024-08-20 | CVE-2024-5576 | Cross-site Scripting vulnerability in Themeum Tutor LMS Elementor Addons The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carousel_skin' attribute within the plugin's Course Carousel widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-27 | CVE-2024-29913 | Unspecified vulnerability in Themeum Tutor LMS Elementor Addons Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons allows Stored XSS.This issue affects Tutor LMS Elementor Addons: from n/a through 2.1.3. | 5.4 |