Description
WordPress Plugin Tutor LMS-eLearning and online course solution is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to delete any course. WordPress Plugin Tutor LMS-eLearning and online course solution version 2.7.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.1 or latest
References
Related Vulnerabilities
WordPress Plugin Htaccess by BestWebSoft Cross-Site Scripting (1.4)
Moodle CVE-2022-40314 Vulnerability (CVE-2022-40314)
WordPress Plugin Ketchup Restaurant Reservations Multiple Vulnerabilities (1.0.0)
WordPress Plugin Live Comment Preview Cross-Site Scripting (2.0.2)
WordPress Plugin TinyMCE Custom Styles Cross-Site Scripting (1.1.2)