Unauthorized Data Deletion Vulnerability in Tutor LMS Plugin by WordPress
CVE-2024-1502
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 March 2024
What is CVE-2024-1502?
The Tutor LMS plugin for WordPress has a significant vulnerability that permits authenticated users with subscriber-level access and higher to delete posts due to a missing capability check in the tutor_delete_announcement() function. This flaw is present in all versions of the plugin up to and including version 2.6.1, potentially leading to unauthorized data loss and disruption of services for website administrators and users.
Affected Version(s)
Tutor LMS β eLearning and online course solution 0 <= 2.6.1