Executive brief
Tutor LMS is a popular WordPress LMS (learning management system) plugin used to deliver online courses. The plugin fails to verify course enrollment before displaying lesson discussion comments, allowing any logged-in user to read comments from courses they do not have access to—including moderation-pending comments. This breaks course access controls and exposes sensitive discussion content.
Technical details
The vulnerability is an improper access control flaw (CWE-200, OWASP A3) in the lesson discussion content endpoint. The plugin does not validate that the authenticated user is enrolled in or has permission to access a specific course before returning its lesson comments. An attacker with any valid WordPress account (subscriber or higher) can bypass enrollment checks via direct API requests or page access, retrieving lesson discussion content and comments pending moderation. The vulnerability affects versions 4.0.0 through 4.0.7; a patch was released in version 4.0.8.
Affected products
- Tutor Tutor LMS 4.0.0 to 4.0.7
Timeline
- 2026-09-14: disclosed
- 2026-09-16: patched: Fixed in version 4.0.8