Description
WordPress Plugin Tutor LMS-eLearning and online course solution is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently enable user registration. WordPress Plugin Tutor LMS-eLearning and online course solution version 2.6.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.0 or latest
References
Related Vulnerabilities
WordPress Plugin FV Flowplayer Video Player Multiple Vulnerabilities (7.3.14.727)
WordPress Plugin Contextual Related Posts Cross-Site Request Forgery (2.9.3)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3663)
Chamilo Missing Authorization Vulnerability (CVE-2025-59544)
WordPress Plugin Comprehensive Google Map Cross-Site Request Forgery (9.1.3)