Impact
The Tutor LMS WordPress plugin does not verify that a user has permission to view a course before returning lesson discussion content. As a result, any authenticated user, such as a subscriber, can access private comments from courses they have not enrolled in, including those awaiting moderation. This leak exposes sensitive discussion data and can compromise learner privacy, representing an improper privilege management flaw.
Affected Systems
Tutor LMS WordPress plugin versions prior to 4.0.8, including 4.0.0 through the latest incomplete releases before the 4.0.8 update. Any site running these versions of the plugin is vulnerable, regardless of additional security plugins or WordPress configurations.
Risk and Exploitability
The vulnerability only requires an authenticated WordPress user; any subscriber has such access. An attacker can retrieve comments from unregistered courses, including unmoderated posts. The CVSS score of 4.3 indicates a medium severity, and the EPSS score of <1% shows a low probability of exploitation. The plugin is not listed in CISA's KEV catalog. Because the flaw exposes private commentary data and could reveal sensitive learner interactions, prompt remediation is advisable even though the exploitation risk is low.
OpenCVE Enrichment