cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, CVE-2024-10393

CVE, Research URL

CVE-2024-10393

Published on
Nov 21, 2024
Research Description
Tutor LMS &#8211; eLearning and online course solution [tutor] < 2.7.7 CVE-2024-10393 [en] The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
Affected versions
Min -, max 2.7.7.
Status
vulnerable