Vulnerability Description
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include any local php file
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Themeum | Tutor Lms | < 1.8.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/20f3e63a-31d8-49a0-b4ef-209749feff5cExploitThird Party Advisory
- https://wpscan.com/vulnerability/20f3e63a-31d8-49a0-b4ef-209749feff5cExploitThird Party Advisory
FAQ
What is CVE-2021-24242?
CVE-2021-24242 is a vulnerability with a CVSS score of 3.8 (LOW). The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plu...
How severe is CVE-2021-24242?
CVE-2021-24242 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24242?
Check the references section above for vendor advisories and patch information. Affected products include: Themeum Tutor Lms.