Tutor LMS
cpe:2.3:a:themeum:tutor_lms:*:*:*:*:wordpress:*:*
- < 3.9.13
A vulnerability exists in the Tutor LMS WordPress plugin in versions prior to 3.9.13. The issue arises because the plugin does not properly verify if a user has the right to edit a specific post before overwriting it in one of its content-builder save handlers. Instead, it only checks against an unrelated identifier. This flaw allows authenticated users with instructor-level access to overwrite and take control of any post or page on the site, including those owned by administrators.
Exploitation of this vulnerability allows for unauthorized overwriting and takeover of posts or pages, potentially leading to misuse of administrative content.
Users are advised to update the Tutor LMS WordPress plugin to version 3.9.13 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.