Vulnerabilities > CVE-2024-5784 - Missing Authorization vulnerability in Tutorlms Tutor LMS PRO

047910
CVSS 6.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
LOW
network
low complexity
tutorlms
CWE-862

Summary

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.

Vulnerable Configurations

Part Description Count
Application
Tutorlms
1

Common Weakness Enumeration (CWE)