Cross-site Scripting in Themeum Tutor LMS BunnyNet Integration
CVE-2026-24584
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 January 2026
What is CVE-2026-24584?
The Themeum Tutor LMS BunnyNet Integration plugin is susceptible to a cross-site scripting vulnerability due to improper neutralization of input during web page generation. This flaw allows for DOM-based XSS attacks, which can be exploited by an attacker to execute arbitrary scripts in the context of the affected user's session. Those using versions up to and including 1.0.0 should take immediate measures to mitigate risks.
Affected Version(s)
Tutor LMS BunnyNet Integration 0 <= 1.0.0