CVE · High

CVE-2024-43142 — Tutor LMS – eLearning and online course solution [tutor] < 2.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-43142 Tutor LMS – eLearning and online course solution [tutor] < 2.7.4 Missing Authorization High 8.8 < 2.7.4 2.7.4 2024-08-07

CVE-2024-43142

The Tutor LMS plugin for WordPress through version 2.7.3 fails to verify user permissions in the create_or_update_annoucement, tutor_quiz_save, tutor_load_edit_lesson_modal, and tutor_modal_create_or_update_lesson functions, allowing authenticated users with instructor-level capabilities or higher to alter data beyond their authorized scope. This vulnerability enables attackers to make unauthorized changes to course content and related information that they should not be able to modify. The flaw has been resolved in version 2.7.4 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.