Executive brief
Tutor LMS is a popular WordPress plugin used to create and manage online courses and learning platforms. A security flaw in versions 3.9.7 and earlier allows unauthorized individuals to perform actions or access data that should be restricted to administrators or specific users. This could lead to unauthorized changes to course content or the exposure of internal information, potentially impacting the integrity of the learning platform.
Technical details
A broken access control vulnerability exists in the Tutor LMS plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. An unauthenticated remote attacker can exploit this flaw by sending crafted network requests to the affected site, allowing them to execute actions or access data without proper permissions. The vulnerability is present in versions up to and including 3.9.7. The issue was addressed in version 3.9.8, which implements the necessary authorization and nonce token checks to prevent unauthorized access.
Affected products
- Themeum Tutor LMS <= 3.9.7
Timeline
- 2026-02-17: other: Vulnerability reported by researcher
- 2026-04-20: advisory: Patchstack published initial advisory
- 2026-04-20: patched: Fixed in version 3.9.8
- 2026-06-15: disclosed: CVE published to NVD