The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow authenticated attackers, with Instructor-level permissions and above, to delete any course.
References
Configurations
History
24 Jan 2025, 17:03
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:* | |
First Time |
Themeum
Themeum tutor Lms |
|
CWE | CWE-639 | |
References | () https://plugins.trac.wordpress.org/browser/tutor/trunk/classes/Course_List.php#L357 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3086489/ - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/45d04643-e43a-4732-91bf-e4af7b622e33?source=cve - Third Party Advisory |
Information
Published : 2024-05-16 06:15
Updated : 2025-01-24 17:03
NVD link : CVE-2024-4279
Mitre link : CVE-2024-4279
CVE.ORG link : CVE-2024-4279
JSON object : View
Products Affected
themeum
- tutor_lms
CWE
CWE-639
Authorization Bypass Through User-Controlled Key