The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-46935 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00262}

epss

{'score': 0.00355}


Fri, 11 Jul 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum tutor Lms
CPEs cpe:2.3:a:tutorlms:tutor_lms_pro:*:*:*:*:*:wordpress:*:* cpe:2.3:a:themeum:tutor_lms:*:*:*:*:pro:wordpress:*:*
Vendors & Products Tutorlms
Tutorlms tutor Lms Pro
Themeum
Themeum tutor Lms

Tue, 03 Sep 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Tutorlms
Tutorlms tutor Lms Pro
CPEs cpe:2.3:a:tutorlms:tutor_lms_pro:*:*:*:*:*:wordpress:*:*
Vendors & Products Tutorlms
Tutorlms tutor Lms Pro

Fri, 30 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Aug 2024 03:45:00 +0000

Type Values Removed Values Added
Description The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
Title Tutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object Reference
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-30T14:39:05.512Z

Reserved: 2024-06-10T08:27:03.121Z

Link: CVE-2024-5784

cve-icon Vulnrichment

Updated: 2024-08-30T14:39:01.219Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-30T04:15:08.193

Modified: 2025-07-11T19:58:55.617

Link: CVE-2024-5784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.