{
 "id": "WPSEC-2026-0515",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0515/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0515/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0515/index.md",
 "title": "Tutor LMS <= 4.1.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Quiz Grade Manipulation via Quiz Attempt Submission",
 "description": "The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via quiz attempt submission. The submission handler scored true/false and single-choice questions by looking up the submitted answer ID without checking that it belongs to the question, accepted question IDs from other quizzes, and accepted new answers for attempts that had already ended. This makes it possible for authenticated attackers with subscriber-level access who can take a quiz to mark their answers correct by referencing correct answers of other questions and to re-submit finished attempts, manipulating their quiz grades.",
 "plugin": {
  "slug": "tutor",
  "name": "Tutor LMS",
  "full_name": "Tutor LMS – eLearning and online course solution",
  "wordpress_org": "https://wordpress.org/plugins/tutor/",
  "advisories_url": "https://wpsec.com/vuln/plugin/tutor/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/tutor"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.1.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.1.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.1.1",
 "remediation": "Update to 4.1.1 or later.",
 "fix_released": "2026-10-06T11:07:46+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-06T14:18:51.926593+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0515/",
  "https://plugins.svn.wordpress.org/tutor/tags/4.1.1/",
  "https://wordpress.org/plugins/tutor/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/tutor",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}