Impact
The Tutor LMS WordPress plugin before 3.9.14 contains a flaw that fails to verify a user’s course enrollment when displaying protected lesson, quiz, or assignment content. Because of this, authenticated users who have subscriber or higher privileges and are enrolled in at least one course can view paid content from courses to which they are not enrolled. This allows inadvertent disclosure of copyrighted or monetized learning materials, which compromises confidentiality and potentially revenue models. The weakness is a form of improper access control (CWE‑639).
Affected Systems
Any WordPress site running Tutor LMS version earlier than 3.9.14 is affected. The vulnerability applies to all users with subscriber-level or higher roles who have enrolled in one or more courses, regardless of the courses they are not enrolled in. Failed enrollment checks occur across the plugin’s lesson, quiz, and assignment modules, exposing content belonging to other courses. Site administrators should verify whether their installations use a vulnerable plugin version, and identify users who may have obtained unauthorized access through this path.
Risk and Exploitability
The CVSS base score is 4.3, representing a moderate impact. EPSS is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated user with subscriber-level privileges; it requires that an attacker possess a legitimate WordPress account and have enrolled in at least one course. Once authenticated, the attacker can navigate to other courses’ content pages and bypass the enrollment check to retrieve paid lesson, quiz, or assignment resources. Because it is an insider‑type threat that relies on legitimate credentials, mitigating this flaw primarily depends on applying the vendor‑issued update or otherwise restricting access controls.
OpenCVE Enrichment