Access violation vulnerability in Tutor LMS – eLearning and online course solution 3.8.3

The Tutor LMS is a plugin for WordPress that helps create online courses. However, it has a security vulnerability that allows unauthorized people to change data without permission. This happens because the plugin does not check for the proper permissions when verifying webhook signatures. This affects all versions of the plugin up to 3.8.3. As a result, attackers can make fake requests with a payment type of ‘recurring’ to mark orders as paid without actually paying.

Detected in:

Tutor LMS – eLearning and online course solution fixed vulnerable versions: >= * <= 3.8.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.