nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-10393 CVE-2024-10393
MEDIUM
Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration
Record summary
CVE-2024-10393 has a selected CVSS score of 5.3 (medium).
Description
The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Tutor LMS – eLearning and online course solutionBrowse themeum / Tutor LMS – eLearning and online course solutionDefault status: unaffected | CVE List | Through 2.7.6 | affected |
tutor_lmsBrowse themeum / tutor_lmsDefault status: unknown | CVE List | Through 2.7.6 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3186319/tutor wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/bf8aa169-df51-46db-8c65-f1543d4f75f9?source=cve