cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, CVE-2023-3133

CVE, Research URL

CVE-2023-3133

Published on
Jul 04, 2023
Research Description
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
Affected versions
Min -, max 1.9.11.
Status
vulnerable