Executive brief
Tutor LMS is a popular WordPress plugin that provides learning management system functionality. A flaw in the plugin's REST API authentication allows someone with a read-only API key to escalate privileges and perform administrative actions, potentially compromising the entire site and its student data.
Technical details
The vulnerability is an authentication bypass and privilege escalation flaw in Tutor LMS versions before 4.0.8. The plugin fails to correctly identify which REST API requests belong to its own API endpoints and does not properly enforce permission levels associated with API credentials. An attacker in possession of a read-only API key can craft requests that are misclassified, allowing them to act with administrator privileges under the account that issued the key. The vulnerability requires network access to the WordPress REST API endpoint. Patches are available in version 4.0.8 and later.
Affected products
- Themeum Tutor LMS 2.7.1 before 4.0.8
Timeline
- 2026-09-14: disclosed
- 2026-09-16: advisory: Published in NVD