Junglewise Threat Intelligence

CVE-2026-12271: Themeum Tutor LMS IDOR in quiz attempt modification

CVE-2026-12271 · Severity: info · CVSS 5.4 · Published 2026-07-13

Technologies: Themeum Tutor LMS. Vendors: Themeum.

Executive brief

Tutor LMS is a popular WordPress plugin used to create and manage online courses and quizzes. A security flaw allows students to modify or force-complete the quiz attempts of other students. This could result in unauthorized changes to grades, pass/fail results, and the integrity of educational records within the platform.

Technical details

An Insecure Direct Object Reference (IDOR) exists in the quiz answering logic of Tutor LMS before version 3.9.13. The vulnerability occurs because the plugin performs an ownership check on a scalar 'attempt_id' parameter but subsequently uses keys from an 'attempt' array parameter to perform database writes. An attacker with subscriber-level access can provide their own valid attempt ID to pass the initial authorization check, while using a victim's attempt ID as the array key to overwrite the victim's quiz data. This allows an attacker to modify answers, change earned marks, and force-complete in-progress quizzes belonging to other users. The issue is fixed in version 3.9.13.

Affected products

  • Themeum Tutor LMS < 3.9.13

Timeline

  • 2026-06-22: disclosed: Publicly published by WPScan
  • 2026-07-13: advisory: NVD publication date
  • 2026-07-13: patched: Fixed in version 3.9.13

References

Related threats