Impact
The Tutor LMS WordPress plugin does not verify that a user has permission to view a course before returning lesson discussion content. As a result, any authenticated user, such as a subscriber, can access private comments from courses they have not enrolled in, including those awaiting moderation. This leak exposes sensitive discussion data and can compromise learner privacy. The weakness is a classic example of improper privilege management.
Affected Systems
Tutor LMS WordPress plugin versions prior to 4.0.8, including 4.0.0 through the latest incomplete releases before the 4.0.8 update. Any site running these versions of the plugin is vulnerable, regardless of additional security plugins or WordPress configurations.
Risk and Exploitability
The exploit requires only an authenticated WordPress account, which is commonly available to subscribers. Because the vulnerability is local to authenticated users and the EPSS score is less than 1%, the likelihood of exploitation is low, and the plugin is not listed in CISA's KEV catalog. However, the confidentiality impact and the ability for widespread comment leaks warrant prompt action. The CVSS score is not provided, but the nature of the disclosure suggests a high severity concerning data privacy.
OpenCVE Enrichment