Executive brief
Tutor LMS is a WordPress plugin that delivers online courses and learning content. An authenticated attacker with basic subscriber access can enumerate user IDs to expose email addresses and phone numbers of any WordPress user, including administrators, by exploiting missing validation on a user identifier parameter.
Technical details
The plugin fails to validate the student_id parameter, allowing authenticated users to access arbitrary user profile data via insecure direct object reference. An attacker with subscriber-level access can iterate through user IDs to disclose sensitive information such as email and phone numbers. The vulnerability affects all versions up to and including 4.0.8.
Affected products
- Tutor LMS Project Tutor LMS up to and including 4.0.8
Timeline
- 2026-09-19: disclosed