CVE-2024-10393

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
21/11/2024
Last modified:
23/01/2025

Description

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:* 2.7.6 (including)