Tutor LMS <= 4.1.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Quiz Grade Manipulation via Quiz Attempt Submission
- ID
- WPSEC-2026-0515
- Plugin
- Tutor LMS – eLearning and online course solution (tutor)
- Affected
- all versions before 4.1.1
- Remediation
- Update to 4.1.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Tutor LMS on WPSec AttackSurface
- Fix released
- Published
Description
The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via quiz attempt submission. The submission handler scored true/false and single-choice questions by looking up the submitted answer ID without checking that it belongs to the question, accepted question IDs from other quizzes, and accepted new answers for attempts that had already ended. This makes it possible for authenticated attackers with subscriber-level access who can take a quiz to mark their answers correct by referencing correct answers of other questions and to re-submit finished attempts, manipulating their quiz grades.
References
- https://wpsec.com/vuln/WPSEC-2026-0515/
- https://plugins.svn.wordpress.org/tutor/tags/4.1.1/
- https://wordpress.org/plugins/tutor/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS