Impact
The Tutor LMS plugin contains a race condition that occurs when multiple concurrent requests access shared resources without proper synchronization. An attacker could exploit this by triggering simultaneous operations that the plugin does not guard against, potentially leading to data corruption or inconsistencies in course and student records. If these inconsistencies propagate to the user interface, students might see incorrect grades or course material, and administrators could experience erratic system behavior.
Affected Systems
All installations of the WordPress Tutor LMS plugin from its earliest release through version 4.1.1 are affected. The plugin, developed by Themeum, is commonly deployed on WordPress sites hosting online courses. Sites that have not upgraded beyond 4.1.1 remain vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is concurrent user or background requests; no special privileges are required. Although a public exploit is not known, the moderate risk and widespread use of the plugin mean that high‑traffic sites could be targeted in the future.
OpenCVE Enrichment