Tutor LMS
cpe:2.3:a:themeum:tutor_lms:*:*:*:*:wordpress:*:*
- < 3.9.13
A vulnerability exists in the Tutor LMS WordPress plugin in versions prior to 3.9.13, where the plugin fails to implement proper authorization or validation before allowing comments to be created. This flaw enables authenticated users with subscriber-level access and above to post comments that are automatically approved, including arbitrary HTML and links, on any content site-wide. The vulnerability bypasses the standard comment moderation process.
Exploitation of this vulnerability allows for the creation of comments that contain unfiltered HTML and links, which could be used for phishing or to distribute malware. The comments are also automatically approved, bypassing any moderation.
To reproduce this vulnerability, log in as a subscriber user. Once logged in, extract the '_tutor_nonce' which is available to subscribers. This nonce can be used to authenticate a request to the 'tutor_create_lesson_comment' action via 'admin-ajax.php'. Include the nonce and the comment content, which can contain HTML and scripts, in the request. The comment will be posted on the specified 'comment_post_ID' and will be automatically approved.
Users are advised to update the Tutor LMS WordPress plugin to version 3.9.13 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.