PT-2024-30162 · WordPress · The Tutor Lms

Thanh Nam Tran

·

Published

2024-05-16

·

Updated

2025-01-24

·

CVE-2024-4279

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Tutor LMS – eLearning and online course solution plugin for WordPress versions up to, and including, 2.7.0
Description The issue allows authenticated attackers with Instructor-level permissions and above to delete any course due to missing validation on a user-controlled key in the tutor course delete function. This can be exploited via the tutor course delete function.
Recommendations For versions up to, and including, 2.7.0, consider disabling the tutor course delete function until a patch is available to prevent arbitrary course deletion. Restrict access to the course deletion functionality to minimize the risk of exploitation.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-4279

Affected Products

The Tutor Lms