The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 77.0%