# Tutor LMS <= 4.1.0 - Authenticated (Tutor Instructor+) Insecure Direct Object Reference to Arbitrary Post Overwrite via Course Creation 'ID' Parameter

- **ID:** WPSEC-2026-0516
- **Plugin:** Tutor LMS – eLearning and online course solution (`tutor`), https://wordpress.org/plugins/tutor/
- **Affected versions:** from 3.0.0 before 4.1.1
- **Fixed in:** 4.1.1 (Update to 4.1.1 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/tutor
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0516/

## Description

The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 3.0.0 to 4.1.0 via the course creation AJAX action. The handler only checked that the user is an instructor and passed all submitted fields, including a user-supplied 'ID', to the post insert function, which updates the existing post with that ID instead of creating a new one. This makes it possible for authenticated attackers with Tutor Instructor-level access and above to overwrite courses owned by other instructors and other existing posts and pages, which are converted into courses and, in the default configuration, reassigned to the attacker.

## References

- https://wpsec.com/vuln/WPSEC-2026-0516/
- https://plugins.svn.wordpress.org/tutor/tags/4.1.1/
- https://wordpress.org/plugins/tutor/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0516/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
