Description
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.
Published: 2026-01-22
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Authorization Bypass through a User‑Controlled Key in the WordPress Tutor LMS plugin from Themeum. It allows a malicious user to supply arbitrary identifiers that bypass improperly configured access controls and access or modify resources that should be restricted, such as private course content and user data. This weakness falls under CWE‑639, indicating a failure to confirm user authority before granting access. The impact includes potential disclosure of confidential educational materials and alteration or deletion of course contents, compromising the confidentiality and integrity of the site.

Affected Systems

WordPress sites that run the Themeum Tutor LMS plugin version 3.9.4 or earlier are affected. The flaw exists in all releases of the plugin from its earliest versions through 3.9.4, so any deployment with an older version requires assessment.

Risk and Exploitability

The CVSS score of 3.8 classifies the issue as moderate in severity, and the EPSS score of less than 1% indicates a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, as the issue involves specific HTTP requests to the plugin’s endpoints; this is inferred from the description, as the exact vector is not explicitly stated. An attacker can craft requests that include a user‑controlled key to gain unauthorized access to protected resources, but the requirement for knowledge of identifiers reduces the overall risk level.

Generated by OpenCVE AI on April 30, 2026 at 14:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Tutor LMS plugin to a version newer than 3.9.4 to eliminate the IDOR flaw.
  • If an immediate update cannot be performed, restrict access to the plugin’s endpoints by enforcing role‑based access controls or configuring web‑server rules to block non‑privileged users from reaching the vulnerable URLs.
  • If the Tutor LMS functionality is not essential, remove or deactivate the plugin from the WordPress installation until a secure version is released.

Generated by OpenCVE AI on April 30, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Mon, 26 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum tutor Lms
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum tutor Lms
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.
Title WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References

Subscriptions

Themeum Tutor Lms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:45.379Z

Reserved: 2025-05-07T09:40:00.791Z

Link: CVE-2025-47555

cve-icon Vulnrichment

Updated: 2026-01-26T22:01:34.252Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:15:54.770

Modified: 2026-04-27T19:16:13.960

Link: CVE-2025-47555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:15:40Z

Weaknesses