Fiche vulnérabilité
CVE-2023-3133 : faille élevée themeum tutor lms (CVSS 7.5)
Description
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 4 juil. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- themeum tutor lms