CyberRota Analysis
AI-GeneratedThe Tutor LMS WordPress plugin prior to version 4.0.0 is vulnerable due to improper access control, allowing authenticated users with subscriber-level permissions to read and inject replies into Q&A threads of courses they do not own. This could lead to unauthorized information disclosure and potential misinformation within course discussions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them.