Description
WordPress Plugin Tutor LMS-eLearning and online course solution is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add, modify, or delete data. WordPress Plugin Tutor LMS-eLearning and online course solution version 2.7.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.1 or latest
References
Related Vulnerabilities
Apache Tomcat Improper Certificate Validation Vulnerability (CVE-2018-8034)
Moodle Other Vulnerability (CVE-2022-40208)
WordPress Plugin Events by Devllo Cross-Site Scripting (1.0.4.2)
WordPress Plugin DSGVO All in one for WP Cross-Site Scripting (4.1)
WordPress Plugin jcwp youtube channel embed Cross-Site Scripting (1.5.2)