CVE-2023-3133: Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API
Published Jul 4, 2023
·Updated
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
Affected Software
1 affected component
Themeum Tutor Lms Wordpress<2.2.1
Event History
Jul 4, 2023
CVE Published
via MITRE·07:23 AM
Data Sourced
via MITRE·07:23 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-3133?
CVE-2023-3133 is a vulnerability in the Tutor LMS WordPress plugin before version 2.2.1 that allows unauthenticated attackers to access information from Lessons that should not be publicly available.
2
How severe is CVE-2023-3133?
CVE-2023-3133 has a severity value of 7.5, which is considered high.
3
What software is affected by CVE-2023-3133?
The Tutor LMS WordPress plugin before version 2.2.1 is affected by CVE-2023-3133.
4
How do I fix CVE-2023-3133?
To fix CVE-2023-3133, you should upgrade your Tutor LMS WordPress plugin to version 2.2.1 or newer.