Impact
The vulnerability arises when Tutor LMS's comment creation handlers omit authorization checks and input validation before storing user comments. As a result, any authenticated user with a subscriber role or higher can submit comments that are immediately marked as approved. Because the content is stored without sanitization, the comments may contain arbitrary HTML and links, enabling cross‑site scripting, defacement, or phishing attacks on site visitors.
Affected Systems
WordPress sites running the Tutor LMS plugin prior to version 3.9.13 are affected. The issue applies to any content that accepts comments higher can exploit it.
Risk and Exploitability
The CVSS score is 4.3, the EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. The flaw gives authenticated users the ability to inject arbitrary content site‑wide, bypassing moderation queues. Likely attack vectors involve standard comment submission endpoints, requiring only the subscriber privilege level and no additional exploitation steps. The overall risk defacement, and link‑based phishing.
OpenCVE Enrichment