ZeroHour

CVE-2023-3133

PoC
CVSS 3.1
7.5 high
EPSS
<1%p60
Published
()
Modified
Description

The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.

Vendors
themeum
Products
tutor lms
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.