PT-2026-96663 · WordPress · Tutor Lms
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tutor LMS – eLearning and online course solution plugin for WordPress versions prior to 4.0.8
Description
An Insecure Direct Object Reference (IDOR) exists via the
tutor quiz builder save AJAX action. The issue occurs because the system fails to validate whether nested question id, answer id, deleted question ids[], and deleted answer ids[] values in the submitted payload belong to a quiz, topic, or course that the requester is authorized to manage. While the handler validates top-level course id, topic id, and ID values, the nested identifiers are passed directly into database update and delete statements within the save questions(), save question answers(), and handle delete() functions. This allows authenticated attackers with Instructor-level access or higher to overwrite content, re-parent arbitrary quiz questions and answers belonging to other instructors or administrators, and delete arbitrary quiz question and answer rows.Recommendations
Update the plugin to version 4.0.8 or later.
As a temporary mitigation, restrict access to the
tutor quiz builder save AJAX action for users with Instructor-level permissions until the update is applied.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tutor Lms