PT-2026-95740 · WordPress · Tutor Lms

·

CVE-2026-88944

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS versions prior to 4.0.9
Description The Tutor LMS plugin for WordPress contains an authorization bypass that allows authenticated users with subscriber-level access or higher to permanently delete arbitrary WordPress posts, such as pages, courses, quizzes, and WooCommerce products. This occurs because the plugin fails to properly verify if a user is authorized to perform the deletion action via the wp delete post() function. The exploitation process involves triggering the profile-photo upload flow to obtain an authored attachment row, creating a Tutor topic linked to that attachment, and then calling the lesson deletion handler using a target post ID through the lesson id parameter.
Recommendations Update the plugin to version 4.0.9 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88944

Affected Products

Tutor Lms