CVE-2024-4351
- EPSS 28.12%
- Veröffentlicht 16.05.2024 10:15:09
- Zuletzt bearbeitet 22.01.2025 18:23:35
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possib...
CVE-2024-4222
- EPSS 0.58%
- Veröffentlicht 16.05.2024 10:15:08
- Zuletzt bearbeitet 22.01.2025 18:23:01
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for un...
CVE-2024-4223
- EPSS 2.29%
- Veröffentlicht 16.05.2024 09:15:15
- Zuletzt bearbeitet 24.01.2025 17:58:19
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauth...
CVE-2024-4318
- EPSS 0.65%
- Veröffentlicht 16.05.2024 06:15:11
- Zuletzt bearbeitet 24.01.2025 17:11:02
The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
CVE-2024-4279
- EPSS 0.22%
- Veröffentlicht 16.05.2024 06:15:10
- Zuletzt bearbeitet 24.01.2025 17:03:18
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing val...
CVE-2024-3553
- EPSS 0.3%
- Veröffentlicht 02.05.2024 17:15:26
- Zuletzt bearbeitet 15.01.2025 18:36:47
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices function in all versions up to, and including, 2.6.2. This makes it pos...
CVE-2024-3994
- EPSS 0.27%
- Veröffentlicht 25.04.2024 10:15:09
- Zuletzt bearbeitet 15.01.2025 18:36:21
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tutor_instructor_list' shortcode in all versions up to, and including, 2.6.2 due to insufficient input sanitizati...
CVE-2024-1503
- EPSS 0.12%
- Veröffentlicht 21.03.2024 02:51:43
- Zuletzt bearbeitet 15.01.2025 18:35:32
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the erase_tutor_data() function...
CVE-2024-1502
- EPSS 0.08%
- Veröffentlicht 21.03.2024 02:51:43
- Zuletzt bearbeitet 15.01.2025 18:34:26
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. This makes...
CVE-2024-1751
- EPSS 35.25%
- Veröffentlicht 13.03.2024 16:15:26
- Zuletzt bearbeitet 15.01.2025 18:23:47
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter ...