Impact
The vulnerability is a missing authorization flaw in the Tutor LMS plugin that allows unprivileged users to access or modify data that should be protected, enabling unauthorized modification of course material or viewing of private information. (CWE-862)
Affected Systems
Affected systems include the Themeum Tutor LMS WordPress plugin for all installations running version 3.9.5 or earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity; the EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is through standard WordPress authentication mechanisms, with the attacker exploiting an incorrectly configured access control check within the plugin’s web interface.
OpenCVE Enrichment