Tutor LMS
cpe:2.3:a:themeum:tutor_lms:*:*:*:*:wordpress:*:*
- < 3.9.13
A vulnerability exists in the Tutor LMS WordPress plugin in versions prior to 3.9.13, specifically within the Droip and Kirki page-builder integrations. The plugin fails to apply the necessary checks for enrollment, purchase, and private-course capabilities that are enforced in its main course management system. As a result, authenticated users with subscriber-level access can unauthorizedly enroll in paid or private courses, access private course materials, and mark any course as completed, but only on sites where the Droip or Kirki integration is active.
Exploitation of this vulnerability allows for unauthorized enrollment in paid or private courses, access to private course content, and the ability to mark courses as completed.
Users are advised to update the Tutor LMS WordPress plugin to version 3.9.13 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.