漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation
Vulnerability Description
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
WordPress Tutor LMS Elementor Addons 授权问题漏洞
Vulnerability Description
themeum tutor lms elementor addons是themeum公司开源的一款学习管理系统扩展插件。 WordPress Tutor LMS Elementor Addons 4.0.0及之前版本存在授权问题漏洞,该漏洞源于对 `activate_tutor_free()` 和 `activate_elementor_free()` 函数缺失能力检查,可能导致已认证的攻击者(订阅者及以上权限)在未经适当授权的情况下激活Tutor LMS和Elementor插件。
CVSS Information
N/A
Vulnerability Type
N/A