CVE-2024-1804: Tutor LMS – Migration Tool <= 2.2.0 - Missing Authorization in tutor_import_from_xml
The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutorimportfromxml function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to import courses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1804?
CVE-2024-1804 is classified as a medium severity vulnerability due to the potential for unauthorized data modification by authenticated attackers.
How do I fix CVE-2024-1804?
To fix CVE-2024-1804, update the Tutor LMS – Migration Tool plugin to version 2.2.1 or later, which includes the necessary capability checks.
Who is affected by CVE-2024-1804?
CVE-2024-1804 affects all versions of the Tutor LMS – Migration Tool plugin for WordPress up to and including version 2.2.0.
What type of attack does CVE-2024-1804 allow?
CVE-2024-1804 allows authenticated attackers to modify data without proper authorization due to a missing capability check.
Is CVE-2024-1804 easy to exploit?
Yes, CVE-2024-1804 can be easily exploited by authenticated users with subscription privileges.