# Tutor LMS <= 4.1.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Quiz Grade Manipulation via Quiz Attempt Submission

- **ID:** WPSEC-2026-0515
- **Plugin:** Tutor LMS – eLearning and online course solution (`tutor`), https://wordpress.org/plugins/tutor/
- **Affected versions:** all versions before 4.1.1
- **Fixed in:** 4.1.1 (Update to 4.1.1 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/tutor
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0515/

## Description

The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via quiz attempt submission. The submission handler scored true/false and single-choice questions by looking up the submitted answer ID without checking that it belongs to the question, accepted question IDs from other quizzes, and accepted new answers for attempts that had already ended. This makes it possible for authenticated attackers with subscriber-level access who can take a quiz to mark their answers correct by referencing correct answers of other questions and to re-submit finished attempts, manipulating their quiz grades.

## References

- https://wpsec.com/vuln/WPSEC-2026-0515/
- https://plugins.svn.wordpress.org/tutor/tags/4.1.1/
- https://wordpress.org/plugins/tutor/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0515/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
