CVE-2024-1503: Tutor LMS – eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the erasetutordata() function. This makes it possible for unauthenticated attackers to deactivate the plugin and erase all data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This requires the "Erase upon uninstallation" option to be enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1503?
CVE-2024-1503 is classified as a moderate severity vulnerability due to the potential for unauthorized data manipulation.
How do I fix CVE-2024-1503?
To fix CVE-2024-1503, update the Tutor LMS plugin to version 2.6.2 or higher.
What software is affected by CVE-2024-1503?
CVE-2024-1503 affects all versions of the Tutor LMS plugin for WordPress up to and including version 2.6.1.
What type of vulnerability is CVE-2024-1503?
CVE-2024-1503 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is vulnerable to CVE-2024-1503?
Unauthenticated attackers can exploit CVE-2024-1503 if users have the affected version of the Tutor LMS plugin installed.