PT-2026-95740 · WordPress · Tutor Lms
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tutor LMS versions prior to 4.0.9
Description
The Tutor LMS plugin for WordPress contains an authorization bypass that allows authenticated users with subscriber-level access or higher to permanently delete arbitrary WordPress posts, such as pages, courses, quizzes, and WooCommerce products. This occurs because the plugin fails to properly verify if a user is authorized to perform the deletion action via the
wp delete post() function. The exploitation process involves triggering the profile-photo upload flow to obtain an authored attachment row, creating a Tutor topic linked to that attachment, and then calling the lesson deletion handler using a target post ID through the lesson id parameter.Recommendations
Update the plugin to version 4.0.9 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tutor Lms