PT-2024-16241 · WordPress · Tutor Lms
1337_Wannabe
+1
·
Published
2024-11-21
·
Updated
2024-11-21
·
CVE-2024-10393
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tutor LMS plugin for WordPress versions up to, and including, 2.7.6
Description
The issue is due to a missing check for the
users can register option in the register instructor function, allowing unauthenticated attackers to register as the default role on the site, even if registration is disabled.Recommendations
For versions up to, and including, 2.7.6, consider disabling the
register instructor function until a patch is available to prevent unauthorized user registration.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tutor Lms