CVE-2024-5784
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/08/2024
Last modified:
11/07/2025
Description
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:themeum:tutor_lms:*:*:*:*:pro:wordpress:*:* | 2.7.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



