← Späť na vyhľadávanie CVE

CVE-2026-1372

Tutor LMS Elementor Addons

Popis

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.

CVSS 4.3EPSS 0.20400000000000001%Riziko 0.44
Zobraziť zdroj
Zverejnené
2026-07-21 09:16:53
Dotknuté verzie
<=4.0.0
Typ
Webová aplikácia
Posledná úprava
2026-07-22 17:16:56
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N