CVE-2023-0236: medium-severity vulnerability in Tutor LMS
Tutor LMS < 2.0.10 - Reflected Cross-Site Scripting
Published · Updated
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 6.1epss 1.3%
exploitation probability
1.3%top 29% of all CVEs
observed exploitation
nono source reports it
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Tutor LMSRelated CVEs — Tutor LMS
In the same product, most dangerous first.
CVE-2026-19092CRITICALTutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable ShadowingEPSS 2.0%CVE-2023-3133—Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST APIEPSS 1.0%CVE-2026-85569HIGHTutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request MisclassificationEPSS 0.5%CVE-2026-19093MEDIUMTutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video PathEPSS 0.5%CVE-2023-4805MEDIUMTutor LMS < 2.3.0 - Subscriber+ Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-14187LOWTutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure via IDOREPSS 0.3%