Executive brief
Tutor LMS is a popular WordPress plugin used to create and manage online courses. A security flaw in the plugin's Q&A system allows any registered student to view private questions and post unauthorized replies in courses they are not enrolled in. This could lead to the exposure of sensitive course information or the disruption of student-teacher communications.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Tutor LMS plugin due to improper authorization checks in the Q&A management functionality. Specifically, the 'tutor_qna_create_update' AJAX action validates a user's access based on a provided 'course_id' but performs operations (reading and writing) using a 'question_id' that may belong to a different, unauthorized course. An authenticated attacker with Subscriber-level privileges can exploit this by providing a 'course_id' they have access to alongside a 'question_id' from a private course. This allows the attacker to bypass enrollment restrictions to read private Q&A content and inject unauthorized replies. The issue is fixed in version 4.0.0.
Affected products
- Themeum Tutor LMS < 4.0.0
Timeline
- 2026-07-13: disclosed: Publicly published by WPScan
- 2026-07-30: advisory: NVD publication date
- 2026-07-30: patched: Fixed in version 4.0.0