Tutor LMS <= 4.1.0 - Authenticated (Tutor Instructor+) Insecure Direct Object Reference to Arbitrary Post Overwrite via Course Creation 'ID' Parameter
- ID
- WPSEC-2026-0516
- Plugin
- Tutor LMS – eLearning and online course solution (tutor)
- Affected
- from 3.0.0 before 4.1.1
- Remediation
- Update to 4.1.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Weakness
- CWE-639
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Tutor LMS on WPSec AttackSurface
- Fix released
- Published
Description
The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 3.0.0 to 4.1.0 via the course creation AJAX action. The handler only checked that the user is an instructor and passed all submitted fields, including a user-supplied 'ID', to the post insert function, which updates the existing post with that ID instead of creating a new one. This makes it possible for authenticated attackers with Tutor Instructor-level access and above to overwrite courses owned by other instructors and other existing posts and pages, which are converted into courses and, in the default configuration, reassigned to the attacker.
References
- https://wpsec.com/vuln/WPSEC-2026-0516/
- https://plugins.svn.wordpress.org/tutor/tags/4.1.1/
- https://wordpress.org/plugins/tutor/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS