Impact
The Tutor LMS WordPress plugin, in all releases prior to 4.0.8, fails to classify incoming REST requests as originating from the plugin’s own API. Because of this misclassification, the plugin does not enforce the permissions attached to an API credential, allowing a user with a read‑only key to perform actions with administrator privileges. The flaw resides in improper access control over API endpoints, providing unrestricted escalation of privileges.
Affected Systems
Any WordPress installation that has the Tutor LMS plugin installed at a version older than 4.0.8 is affected, regardless of the WordPress core version. Administrators or developers who rely on the plugin’s read‑only keys to restrict instructor access are exposed to this risk.
Risk and Exploitability
The vulnerability is exploitable remotely through the REST API and requires only possession of a read‑only key. Once an attacker submits a request that the plugin misclassifies as internal, they gain full administrator capabilities. The EPSS score is below 1 % and the flaw is not listed in CISA’s KEV catalog, suggesting limited active exploitation to date. Nevertheless, the ability to gain complete administrative control makes the risk severity high, and a typical CVSS assessment would rate it as a severe or critical issue.
OpenCVE Enrichment