Insecure Direct Object Reference in Tutor LMS Plugin for WordPress
CVE-2026-18439

4.3MEDIUM

What is CVE-2026-18439?

The Tutor LMS plugin for WordPress suffers from an Insecure Direct Object Reference vulnerability in versions up to 4.0.7. This issue arises during the 'tutor_quiz_builder_save' AJAX action, where the lack of proper validation allows authenticated users, especially those with Instructor-level access, to manipulate data that should be restricted. Specifically, it allows unauthorized modifications to quiz questions and answers that belong to other users, as the code only performs validation for top-level identifiers like course_id and topic_id. This oversight poses a significant risk, enabling attackers to overwrite content or delete quiz-related entries belonging to other instructors or administrators.

Affected Version(s)

Tutor LMS – eLearning and online course solution 0 <= 4.0.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nakul Chodha
.