CVE-2024-43142: WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7.3.
Affected Software
3 affected components
Themeum Tutor LMS<=2.7.3
WordPress Tutor LMS<=2.7.3
Themeum Tutor Lms Wordpress<2.7.4
Remediation
Information
Update to 2.7.4 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 27, 57234
Event
via NVD·05:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-43142?
CVE-2024-43142 has been classified as a medium severity vulnerability due to missing authorization issues.
2
How do I fix CVE-2024-43142?
To fix CVE-2024-43142, upgrade your Themeum Tutor LMS plugin to version 2.7.4 or later.
3
What impact does CVE-2024-43142 have on my WordPress site?
CVE-2024-43142 can allow unauthorized access to sensitive features of the Tutor LMS, posing a risk of data exposure.
4
Which versions of Tutor LMS are affected by CVE-2024-43142?
CVE-2024-43142 affects all versions of Tutor LMS from n/a up to and including version 2.7.3.
5
Is CVE-2024-43142 actively being exploited?
There is no public information indicating that CVE-2024-43142 is currently being actively exploited.