Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration
2024-11-20 00:00
1337_WannabeStrategic Overview
StatusPatched in 2.7.7
Affected PluginTutor LMS – eLearning and online course solution
Affected Version
<= 2.7.6CVSS5.3Medium
CVE
CVE-2024-10393Vulnerability Overview
The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
Technical Analysis
REMEDIATION: Update to version 2.7.7, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C