Unauthorized Data Deletion Vulnerability in Tutor LMS Plugin by WordPress
CVE-2024-1502
4.3MEDIUM
Summary
The Tutor LMS plugin for WordPress has a significant vulnerability that permits authenticated users with subscriber-level access and higher to delete posts due to a missing capability check in the tutor_delete_announcement() function. This flaw is present in all versions of the plugin up to and including version 2.6.1, potentially leading to unauthorized data loss and disruption of services for website administrators and users.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published