CyberRota Analysis
AI-GeneratedThe Tutor LMS WordPress plugin prior to version 3.9.13 is vulnerable due to insufficient capability checks in its Droip and Kirki page-builder integrations, allowing authenticated users with subscriber-level access to enroll in paid or private courses, access restricted content, and mark courses as completed without proper authorization. This vulnerability poses a significant risk to site integrity and content confidentiality, particularly for educational platforms utilizing these integrations. WordPress site administrators using the affected plugin should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.