The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Themeum
Themeum tutor Lms |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Themeum
Themeum tutor Lms |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-16T08:32:50.538Z
Updated: 2024-08-01T20:33:52.989Z
Reserved: 2024-04-26T00:21:41.464Z
Link: CVE-2024-4223

Updated: 2024-08-01T20:33:52.989Z

Status : Analyzed
Published: 2024-05-16T09:15:15.810
Modified: 2025-01-24T17:58:19.593
Link: CVE-2024-4223

No data.