← back
CVE-2020-8615

CVE-2020-8615

38Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 8.8%
from disclosure to weapon27 days
Published on NVDFeb 4
1st PoC+27d
exploitation probability
8.8%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.