Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33417 | The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled. |
Thu, 23 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:* |
Thu, 21 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeum
Themeum tutor Lms |
|
| CPEs | cpe:2.3:a:themeum:tutor_lms:-:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themeum
Themeum tutor Lms |
|
| Metrics |
ssvc
|
Thu, 21 Nov 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled. | |
| Title | Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:19:28.490Z
Reserved: 2024-10-25T18:18:25.445Z
Link: CVE-2024-10393
Updated: 2024-11-21T14:44:24.548Z
Status : Analyzed
Published: 2024-11-21T11:15:16.040
Modified: 2025-01-23T17:04:21.173
Link: CVE-2024-10393
No data.
OpenCVE Enrichment
No data.
EUVD