Access violation vulnerability in Tutor LMS – Migration Tool 2.2.0

The plugin called Tutor LMS – Migration Tool for WordPress has a security issue that allows people to access data without permission. This happens because the function called tutor_lp_export_xml doesn’t have a check to make sure only authorized people can use it. This means that anyone who is not logged in can export courses, even ones that are supposed to be private or have a password.

Detected in:

Tutor LMS – Migration Tool fixed vulnerable versions: >= * <= 2.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.