Insecure Direct Object Reference in Tutor LMS eLearning Plugin for WordPress
CVE-2026-3371
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 April 2026
What is CVE-2026-3371?
The Tutor LMS plugin for WordPress suffers from an Insecure Direct Object Reference vulnerability that affects all versions up to and including 3.9.7. This flaw arises from inadequate authorization checks in the save_course_content_order() method, which is invoked without any conditions by the AJAX handler responsible for updating course content. While there is a user management check in place, the reliance on attacker-supplied JSON data allows authenticated users, including those with Subscriber access, to manipulate course structures maliciously. This includes detaching lessons from topics, reordering course content, and reassigning lesson ownership across courses, including those owned by administrators. Effective security measures should be implemented to safeguard against unauthorized content management.
Affected Version(s)
Tutor LMS β eLearning and online course solution 0 <= 3.9.7