CyberRota Analysis
AI-GeneratedThe Tutor LMS WordPress plugin prior to version 3.9.14 is vulnerable due to inadequate verification of user enrollment, enabling authenticated users with subscriber-level access or higher to access paid content from courses they are not enrolled in. This flaw poses a risk of unauthorized content exposure, potentially impacting the integrity of course offerings. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses.