CyberRota Analysis
AI-GeneratedThe Tutor LMS WordPress plugin prior to version 3.9.13 is vulnerable, allowing authenticated users with subscriber-level access and higher to manipulate and force-complete other students' quiz attempts without proper ownership verification. This can lead to unauthorized changes in recorded marks and pass/fail results, compromising the integrity of the assessment process. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.