Junglewise Threat Intelligence

CVE-2026-57694: Themeum Tutor LMS IDOR authorization bypass

CVE-2026-57694 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: Themeum Tutor LMS. Vendors: Themeum.

Executive brief

Themeum Tutor LMS, a popular learning management system for WordPress, contains a security flaw that allows users with low-level accounts to bypass intended access controls. By manipulating specific identifiers in web requests, an unauthorized user could potentially modify data or interact with system components they should not have access to. This could lead to unauthorized changes to course content or student records, impacting the integrity of the educational platform.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Themeum Tutor LMS due to an authorization bypass through a user-controlled key. The application fails to properly validate if the authenticated user has the necessary permissions to access or modify a specific object identified by a request parameter. A remote attacker with at least Subscriber-level privileges can exploit this by manipulating these keys to interact with incorrectly configured access control security levels. This allows for unauthorized data modification (Integrity: High) but does not directly facilitate data exfiltration or service disruption according to the CVSS vector. The issue is resolved in version 3.9.14.

Affected products

  • Themeum Tutor LMS <= 3.9.13

Timeline

  • 2026-03-21: disclosed: Reported by TristanInSec
  • 2026-07-06: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published CVE-2026-57694
  • 2026-07-13: patched: Version 3.9.14 released to address the issue

References

Related threats