Junglewise Threat Intelligence

CVE-2026-1372: Themeum Tutor LMS Elementor Addons missing authorization in plugin activation

CVE-2026-1372 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Vendors: Themeum.

Executive brief

The Tutor LMS Elementor Addons plugin for WordPress, which helps integrate course management features with the Elementor page builder, contains a security flaw. This vulnerability allows any logged-in user, even those with the lowest level of access like subscribers, to activate the Tutor LMS and Elementor plugins without permission. While this does not directly expose sensitive data, it allows unauthorized users to modify the site's active plugin configuration.

Technical details

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to missing authorization due to a lack of capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions. These functions are registered as `admin_action_*` handlers, which can be triggered by authenticated users. An attacker with Subscriber-level access or higher can exploit this to programmatically activate the Tutor LMS and Elementor plugins. The vulnerability is present in all versions up to and including 4.0.0. A fix is expected in versions following 4.0.0 based on the provided changeset references.

Affected products

  • Themeum Tutor LMS Elementor Addons up to, and including, 4.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References