Tutor LMS
cpe:2.3:a:themeum:tutor_lms:*:*:*:*:wordpress:*:*
- < 3.9.13
A vulnerability exists in the Tutor LMS WordPress plugin in versions prior to 3.9.13, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts. The plugin fails to verify ownership of quiz attempts before writing to them, enabling users to overwrite recorded marks and pass/fail results. This issue arises from an Insecure Direct Object Reference (IDOR) vulnerability, where the ownership check can be bypassed by manipulating the request data.
Exploitation of this vulnerability allows for unauthorized modification of quiz attempt data, including overwriting marks and changing pass/fail results, potentially leading to improper assessment outcomes.
To reproduce this vulnerability, log in as a subscriber-level user who owns a quiz attempt. Obtain the Tutor nonce from the public course page. Then, send a request to the quiz endpoint, using the nonce and targeting a victim's quiz attempt by manipulating the attempt ID in the request. The victim's attempt will be force-completed and scored based on the attacker's actions, demonstrating the unauthorized modification of quiz data.
Users are advised to update the Tutor LMS WordPress plugin to version 3.9.13 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.