CVE-2023-3133
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
- Affected products
- Tutor Lms
- Themeum Tutor Lms
- < 2.2.1
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.0% (60th percentile)
- NVD status
- Modified
- Published
- 2023-07-04
CVE-2023-3133 at NVD
1 known exploit for CVE-2023-3133
Proof-of-concept code and exploit modules indexed by Sploitus