VYPR
Medium severity5.9NVD Advisory· Published Jan 23, 2026· Updated Apr 15, 2026

CVE-2026-24584

CVE-2026-24584

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS BunnyNet Integration tutor-lms-bunnynet-integration allows DOM-Based XSS.This issue affects Tutor LMS BunnyNet Integration: from n/a through <= 1.0.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-Based XSS in Tutor LMS BunnyNet Integration plugin ≤1.0.0 allows script injection via improper input neutralization; update to 1.0.1.

Vulnerability

Overview

CVE-2026-24584 describes a DOM-Based Cross-Site Scripting (XSS) vulnerability in the WordPress plugin Tutor LMS BunnyNet Integration, affecting versions from n/a through 1.0.0. The issue arises from improper neutralization of user input during web page generation, enabling an attacker to inject malicious scripts that execute in the victim's browser within the context of the vulnerable site. [1]

Exploitation

Details

Exploitation requires user interaction, such as clicking a crafted link or visiting a malicious page. While the attack can be initiated by a privileged user role, successful execution depends on an end-user's action. This DOM-based variant means the payload manipulates the client-side environment, making it harder to detect via server-side filters. [1]

Impact

An attacker can inject arbitrary scripts, redirects, or advertisements into the website, which will execute when visitors load the affected page. This could lead to data theft, session hijacking, or defacement. The vulnerability is rated Medium with a CVSS v3 score of 5.9, and the vendor notes that such XSS flaws are often used in mass-exploit campaigns against WordPress sites. [1]

Mitigation

The vendor has released version 1.0.1, which fixes the issue. Users are strongly advised to update immediately. For those unable to update, temporary measures include requesting assistance from a hosting provider or web developer. Patchstack users can enable auto-updates to apply the fix automatically. [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.