Tutor LMS <= 2.2.0 - Missing Authorization via REST API
2023-06-12 00:00
A. S. M. Muhiminul HasanStrategic Overview
StatusPatched in 2.2.1
Affected PluginTutor LMS – eLearning and online course solution
Affected Version
<= 2.2.0CVSS7.5High
CVE
CVE-2023-3133Vulnerability Overview
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on various REST API endpoints in versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to view quiz questions and answers as well as student quiz attempts and author information such as email addresses.
Technical Analysis
REMEDIATION: Update to version 2.2.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C