PT-2026-96663 · WordPress · Tutor Lms

·

CVE-2026-18439

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS – eLearning and online course solution plugin for WordPress versions prior to 4.0.8
Description An Insecure Direct Object Reference (IDOR) exists via the tutor quiz builder save AJAX action. The issue occurs because the system fails to validate whether nested question id, answer id, deleted question ids[], and deleted answer ids[] values in the submitted payload belong to a quiz, topic, or course that the requester is authorized to manage. While the handler validates top-level course id, topic id, and ID values, the nested identifiers are passed directly into database update and delete statements within the save questions(), save question answers(), and handle delete() functions. This allows authenticated attackers with Instructor-level access or higher to overwrite content, re-parent arbitrary quiz questions and answers belonging to other instructors or administrators, and delete arbitrary quiz question and answer rows.
Recommendations Update the plugin to version 4.0.8 or later. As a temporary mitigation, restrict access to the tutor quiz builder save AJAX action for users with Instructor-level permissions until the update is applied.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18439

Affected Products

Tutor Lms