WordPress · Tutor Lms · CVE-2026-18439
**Name of the Vulnerable Software and Affected Versions**
Tutor LMS – eLearning and online course solution plugin for WordPress versions prior to 4.0.8
**Description**
An Insecure Direct Object Reference (IDOR) exists via the `tutor quiz builder save` AJAX action. The issue occurs because the system fails to validate whether nested `question id`, `answer id`, `deleted question ids[]`, and `deleted answer ids[]` values in the submitted payload belong to a quiz, topic, or course that the requester is authorized to manage. While the handler validates top-level `course id`, `topic id`, and `ID` values, the nested identifiers are passed directly into database update and delete statements within the `save questions()`, `save question answers()`, and `handle delete()` functions. This allows authenticated attackers with Instructor-level access or higher to overwrite content, re-parent arbitrary quiz questions and answers belonging to other instructors or administrators, and delete arbitrary quiz question and answer rows.
**Recommendations**
Update the plugin to version 4.0.8 or later.
As a temporary mitigation, restrict access to the `tutor quiz builder save` AJAX action for users with Instructor-level permissions until the update is applied.