CVE-2024-5784: Tutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object Reference
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treportquizatttemptdelete and tutorgcclassaction in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5784?
CVE-2024-5784 is considered a high severity vulnerability due to its potential for unauthorized administrative actions on WordPress sites using Tutor LMS Pro.
How do I fix CVE-2024-5784?
To fix CVE-2024-5784, you should upgrade the Tutor LMS Pro plugin to version 2.7.3 or later.
What versions of Tutor LMS Pro are affected by CVE-2024-5784?
All versions of Tutor LMS Pro up to and including 2.7.2 are affected by CVE-2024-5784.
What actions can be exploited in CVE-2024-5784?
CVE-2024-5784 allows unauthorized execution of actions such as treport_quiz_attempt_delete and tutor_gc_class_action.
Is my WordPress site at risk if I use Tutor LMS Pro?
Yes, if you are using Tutor LMS Pro version 2.7.2 or earlier, your WordPress site is at risk according to CVE-2024-5784.