Record summary

CVE-2024-4351 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.

Description

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 16, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 24, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 2.7.0affected

Default status: unknown

CVE ListThrough 2.7.0affected

Proofs of concept

1

Repository PoCs

GitHubZSECURE/CVE-2024-4351Repository PoCby ZSECUREStars: 0Not analyzed3 files

1.6 KiB

GitHub

PoC details

References

3