PT-2026-61844 · Themeum · Tutor Lms Elementor Addons

·

CVE-2026-1372

·

Publicado

2026-07-21

·

Atualizado

2026-07-21

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the activate tutor free() and activate elementor free() functions registered as admin action * handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1372

Produtos afetados

Tutor Lms Elementor Addons