CVE-2023-3133
Summary
| CVE | CVE-2023-3133 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-04 08:15:00 UTC |
| Updated | 2023-11-07 04:17:00 UTC |
| Description | The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API WordPress Security Vulnerability | MISC | wpscan.com | |
| 403 Forbidden | MISC | plugins.trac.wordpress.org | |
| Tutor LMS – eLearning and online course solution – WordPress plugin | WordPress.org | MISC | wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.