Impact
A missing validation check on the student_id parameter creates an insecure direct object reference that lets an authenticated user with subscriber or higher privileges read the email address and phone number of any WordPress user. The flaw allows enumeration of user IDs by iterating the parameter, exposing personal data across the site. The weakness is identified as CWE‑639, an improper authorization issue.
Affected Systems
The vulnerability exists in the Tutor LMS – eLearning and online course solution WordPress plugin, affecting all releases up to and including version 4.0.8. Any website running any of these builds is susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. Exploit probability (EPSS) is not available, and the issue is not listed in the CISA KEV catalog. An attacker must first authenticate to the site with a subscriber‑level account or higher and then supply a crafted student_id value. By iterating numeric IDs the attacker can harvest the sensitive information of arbitrary users, including administrators. No public exploits are documented, but the attack vector is straightforward to construct.
OpenCVE Enrichment