Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nakul Chodha

#54351of 57,349
4.3Total CVSS
Vulnerabilities · 1
PT-2026-96663
4.3
2026-09-22
WordPress · Tutor Lms · CVE-2026-18439
**Name of the Vulnerable Software and Affected Versions** Tutor LMS – eLearning and online course solution plugin for WordPress versions prior to 4.0.8 **Description** An Insecure Direct Object Reference (IDOR) exists via the `tutor quiz builder save` AJAX action. The issue occurs because the system fails to validate whether nested `question id`, `answer id`, `deleted question ids[]`, and `deleted answer ids[]` values in the submitted payload belong to a quiz, topic, or course that the requester is authorized to manage. While the handler validates top-level `course id`, `topic id`, and `ID` values, the nested identifiers are passed directly into database update and delete statements within the `save questions()`, `save question answers()`, and `handle delete()` functions. This allows authenticated attackers with Instructor-level access or higher to overwrite content, re-parent arbitrary quiz questions and answers belonging to other instructors or administrators, and delete arbitrary quiz question and answer rows. **Recommendations** Update the plugin to version 4.0.8 or later. As a temporary mitigation, restrict access to the `tutor quiz builder save` AJAX action for users with Instructor-level permissions until the update is applied.