WP Clinic
Log in Sign up

CVE · Medium

CVE-2024-10393 — Tutor LMS – eLearning and online course solution [tutor] < 2.7.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10393 Tutor LMS – eLearning and online course solution [tutor] < 2.7.7 Improper Access Control Medium 5.3 < 2.7.7 2.7.7 2024-11-20

CVE-2024-10393

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.