The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restricted Q&A content due to a missing capability check when interacting with questions in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with subscriber access or higher, to interact with questions in courses in which they are not enrolled including private courses.
History

Wed, 15 Jan 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum tutor Lms
Weaknesses CWE-862
CPEs cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:*
Vendors & Products Themeum
Themeum tutor Lms

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-02-20T18:56:49.287Z

Updated: 2024-08-01T18:26:30.481Z

Reserved: 2024-01-31T17:33:00.570Z

Link: CVE-2024-1133

cve-icon Vulnrichment

Updated: 2024-08-01T18:26:30.481Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-29T01:43:41.283

Modified: 2025-01-15T18:23:26.030

Link: CVE-2024-1133

cve-icon Redhat

No data.