Themeum Tutor LMS Missing Authorization Vulnerability Affects Multiple Versions
CVE-2023-25799
8.3HIGH
What is CVE-2023-25799?
A missing authorization vulnerability exists in Themeum's Tutor LMS, allowing unauthorized users to potentially gain access to sensitive functionalities meant for authenticated users. This flaw can lead to unauthorized actions that compromise the integrity and privacy of user data. The issue affects all versions of Tutor LMS up to 2.1.8, posing a significant security risk for websites utilizing this plugin.
Affected Version(s)
Tutor LMS <= 2.1.8