Tutor LMS – eLearning and online course solution, CVE-2024-10393
- CVE, Research URL
- Published on
- Nov 21, 2024
- Research Description
- Tutor LMS – eLearning and online course solution [tutor] < 2.7.7 CVE-2024-10393 [en] The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
- Affected versions
-
Min -, max 2.7.7.
- Status
-
vulnerable