Vulnerabilities / Tutor LMS / WPSEC-2026-0516

Tutor LMS <= 4.1.0 - Authenticated (Tutor Instructor+) Insecure Direct Object Reference to Arbitrary Post Overwrite via Course Creation 'ID' Parameter

Medium 5.4 CWE-639Fixed in 4.1.1
ID
WPSEC-2026-0516
Plugin
Tutor LMS – eLearning and online course solution (tutor)
Affected
from 3.0.0 before 4.1.1
Remediation
Update to 4.1.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weakness
CWE-639
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Tutor LMS on WPSec AttackSurface
Fix released
Published

Description

The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 3.0.0 to 4.1.0 via the course creation AJAX action. The handler only checked that the user is an instructor and passed all submitted fields, including a user-supplied 'ID', to the post insert function, which updates the existing post with that ID instead of creating a new one. This makes it possible for authenticated attackers with Tutor Instructor-level access and above to overwrite courses owned by other instructors and other existing posts and pages, which are converted into courses and, in the default configuration, reassigned to the attacker.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0