CVE-2023-2919: Tutor LMS <= 2.7.4 - Cross-Site Request Forgery via 'addon_enable_disable'
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addonenabledisable' function. This makes it possible for unauthenticated attackers to enable or disable addons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2919?
CVE-2023-2919 is classified as a moderate severity vulnerability due to the potential for unauthenticated attackers to exploit it.
How do I fix CVE-2023-2919?
To mitigate CVE-2023-2919, update the Tutor LMS plugin to version 2.7.5 or later.
What impact does CVE-2023-2919 have on my website?
CVE-2023-2919 allows attackers to perform unauthorized actions on your site, such as enabling or disabling addons.
What versions of Tutor LMS are affected by CVE-2023-2919?
CVE-2023-2919 affects Tutor LMS versions up to and including 2.7.4.
Is CVE-2023-2919 a remote attack vector?
Yes, CVE-2023-2919 can be exploited remotely since it does not require authentication.