Access violation vulnerability in Tutor LMS Pro 2.7.0

The Tutor LMS Pro plugin for WordPress has a security issue that could allow someone to access, change, or delete data without permission. This is because the plugin does not have a check in place to make sure only authorized users have access to the ‘get_calendar_materials’ function. Additionally, the plugin is vulnerable to a type of attack called SQL Injection, where an attacker could add their own code into the plugin’s existing code to access confidential information from the database. This could be done by someone with subscriber-level permissions or higher.

Detected in:

Tutor LMS Pro fixed vulnerable versions: >= * <= 2.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.