Description
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
Published: 2024-08-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-46935 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00262}

epss

{'score': 0.00355}


Fri, 11 Jul 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum tutor Lms
CPEs cpe:2.3:a:tutorlms:tutor_lms_pro:*:*:*:*:*:wordpress:*:* cpe:2.3:a:themeum:tutor_lms:*:*:*:*:pro:wordpress:*:*
Vendors & Products Tutorlms
Tutorlms tutor Lms Pro
Themeum
Themeum tutor Lms

Tue, 03 Sep 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Tutorlms
Tutorlms tutor Lms Pro
CPEs cpe:2.3:a:tutorlms:tutor_lms_pro:*:*:*:*:*:wordpress:*:*
Vendors & Products Tutorlms
Tutorlms tutor Lms Pro

Fri, 30 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Aug 2024 03:45:00 +0000

Type Values Removed Values Added
Description The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
Title Tutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object Reference
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Themeum Tutor Lms
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:14:23.493Z

Reserved: 2024-06-10T08:27:03.121Z

Link: CVE-2024-5784

cve-icon Vulnrichment

Updated: 2024-08-30T14:39:01.219Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-30T04:15:08.193

Modified: 2025-07-11T19:58:55.617

Link: CVE-2024-5784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses