Description
WordPress Plugin Tutor LMS-eLearning and online course solution is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently enable user registration. WordPress Plugin Tutor LMS-eLearning and online course solution version 2.6.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.0 or latest
References
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9700)
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.14)
MySQL Improper Resource Shutdown or Release Vulnerability (CVE-2026-34317)
Moodle Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-1755)