Vulnerabilities / Tutor LMS / WPSEC-2026-0515

Tutor LMS <= 4.1.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Quiz Grade Manipulation via Quiz Attempt Submission

Medium 4.3 CWE-639Fixed in 4.1.1
ID
WPSEC-2026-0515
Plugin
Tutor LMS – eLearning and online course solution (tutor)
Affected
all versions before 4.1.1
Remediation
Update to 4.1.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-639
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Tutor LMS on WPSec AttackSurface
Fix released
Published

Description

The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via quiz attempt submission. The submission handler scored true/false and single-choice questions by looking up the submitted answer ID without checking that it belongs to the question, accepted question IDs from other quizzes, and accepted new answers for attempts that had already ended. This makes it possible for authenticated attackers with subscriber-level access who can take a quiz to mark their answers correct by referencing correct answers of other questions and to re-submit finished attempts, manipulating their quiz grades.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0