Junglewise Threat Intelligence

CVE-2026-3358: Themeum Tutor LMS unauthorized private course enrollment

CVE-2026-3358 · Severity: medium · CVSS 5.4 · Published 2026-04-11

Technologies: Themeum Tutor LMS. Vendors: Themeum.

Executive brief

Tutor LMS is a popular WordPress plugin used to create and manage online courses. A security flaw allows registered users to enroll themselves in private courses that should not be accessible to them. While the actual course content remains protected by WordPress, the unauthorized enrollment allows users to see private course titles and status on their personal dashboards.

Technical details

The vulnerability exists in the `enroll_now()` and `course_enrollment()` functions within the Tutor LMS plugin due to a lack of `post_status` validation. While the endpoints verify nonces and user authentication, they fail to check if a course is set to 'private' before processing the enrollment. An authenticated attacker with Subscriber-level permissions can bypass intended restrictions by sending a crafted POST request containing a private course ID. This results in an unauthorized enrollment record in the database and exposure of the course title in the user's dashboard, although WordPress core access controls still prevent the viewing of the actual course content (returning a 404 error). The issue is addressed in version 3.9.8.

Affected products

  • Themeum Tutor LMS Up to and including 3.9.7

Timeline

  • 2026-04-11: disclosed
  • 2026-04-11: advisory
  • 2026-04-11: patched: Fixed in version 3.9.8

References