CyberRota Analysis
AI-GeneratedThe Tutor LMS WordPress plugin prior to version 4.0.6 is vulnerable to a critical security flaw that allows unauthenticated users to overwrite internal variables during template rendering, enabling the execution of arbitrary zero-argument PHP functions. This could lead to unauthorized access to sensitive information or system compromise. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.