Access violation vulnerability in Tutor LMS – eLearning and online course solution 2.6.0

The Tutor LMS plugin for WordPress, which helps create online courses, has a security flaw that allows unauthorized users to access restricted question and answer content. This flaw affects all versions up to and including 2.6.0. This means that someone with subscriber access or higher can view and interact with questions in courses they are not enrolled in, including private courses.

Detected in:

Tutor LMS – eLearning and online course solution fixed vulnerable versions: >= * <= 2.6.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.