Sceawere
Vulnerability Detail
CVE-2026-85571UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tutor LMS Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Tutor LMS
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-10T06:16:43.527Z",
"pubdate": "2026-10-10T06:16:43.527Z",
"executiveSummary": "The Tutor LMS WordPress plugin prior to version 4.1.1 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability resulting from insufficient access control validation during course content management operations.\nThis vulnerability allows authenticated users with 'Instructor' privileges to manipulate the parent-child relationships of arbitrary WordPress posts, including those belonging to other instructors or site administrators.\nThe impact is significant, as it enables unauthorized modification of course structures, potentially hijacking proprietary course content, disrupting learning management system functionality, and rendering published educational materials inaccessible to legitimate users.\nSuccessful exploitation requires the attacker to hold an active Instructor account on the WordPress site. No further escalation is required to achieve the primary impact, making this a critical authorization bypass flaw within the plugin's data management logic.\nThe vulnerability highlights a failure to implement server-side verification ensuring that the requested post IDs are owned by or managed by the authenticated requester before processing administrative state changes.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of access control checks within the Tutor LMS course content ordering request handler. Specifically, the application logic fails to validate the ownership or authorization context of the objects being manipulated during the ordering or reassignment process.\nWhen an instructor performs a content ordering action, the plugin processes a request involving specific post IDs intended to reorder elements within a course. Because the plugin does not verify that these post IDs belong to a course the authenticated user is authorized to manage, the system blindly honors the request regardless of the post's original parentage or ownership.\nAn attacker with instructor-level access can craft a malicious request targeting the plugin's API endpoints responsible for course curriculum management. By substituting legitimate post IDs with unauthorized target IDs—such as those belonging to a competitor's course or site-wide content—the attacker forces the plugin to reassign the target content to their own course structure.\nThe attack flow follows these steps: 1) The attacker identifies the Post ID of a target lesson or topic managed by another instructor. 2) The attacker initiates an authorized curriculum update request via the Tutor LMS interface. 3) The attacker intercepts or modifies the request payload to include the unauthorized target Post ID. 4) The server-side logic executes the parent reassignment or ordering logic without confirming that the authenticated Instructor ID possesses the necessary permissions for the target Post ID. 5) The target content is moved, effectively 'stealing' the content from the original course and potentially making it unavailable or incorrectly mapped in the legitimate instructor's dashboard.\nThe scope of this vulnerability includes all versions of Tutor LMS before 4.1.1. The failure is localized to the server-side API or controller responsible for updating post metadata related to course curriculum hierarchy. Post-exploitation impact includes unauthorized content migration, institutional disruption of educational workflows, and the ability to effectively hide content from original instructors by shifting them into foreign course hierarchies."
}