First published: Thu May 16 2024(Updated: )
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=2.7.0 | ||
Themeum Tutor LMS | <2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4222 is considered a critical vulnerability due to the potential for unauthorized access and manipulation of data.
To fix CVE-2024-4222, update the Tutor LMS Pro plugin to version 2.7.1 or later.
CVE-2024-4222 affects all versions of the Tutor LMS Pro plugin up to and including version 2.7.0.
Attackers can gain unauthorized access to add, modify, or delete data due to the missing capability checks.
You can check your installed version of the Tutor LMS Pro plugin against the versions affected by CVE-2024-4222 to determine vulnerability.