CVE · High

CVE-2024-39645 — Tutor LMS – eLearning and online course solution [tutor] < 2.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-39645 Tutor LMS – eLearning and online course solution [tutor] < 2.7.3 Cross-Site Request Forgery (CSRF) High 8.8 < 2.7.3 2.7.3 2024-08-01

CVE-2024-39645

The Tutor LMS plugin for WordPress versions up to 2.7.2 contains a Cross-Site Request Forgery vulnerability resulting from inadequate nonce verification in multiple functions. An unauthenticated attacker could exploit this flaw to remove courses by crafting a malicious request, provided an administrator can be socially engineered into clicking a link. The vulnerability affects all versions prior to 2.7.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.