Impact
The Tutor LMS WordPress plugin before version 3.9.13 fails to verify that the user requesting a quiz attempt modification actually owns that attempt. Because of this ownership check omission, authenticated users with subscriber-level access and higher can change any student’s quiz attempt status, forcing passes or fails and overwriting recorded scores. This flaw embodies CWE‑284 (Broken Access Control) and CWE‑639 (Privilege Dropping or Elevation). The result is a direct compromise of data integrity for assessment records.
Affected Systems
Installations running Tutor LMS older than version 3.9.13 on WordPress sites are vulnerable. The vulnerability applies regardless of site configuration or other plugins; any deployment of a pre‑3.9.13 release is affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. With an EPSS score of less than 1%, publicly known exploits are not currently widespread, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that subscriber or higher roles are common on many sites, making the attack path straightforward for an active user. Based on the description, it is inferred that changes to quiz attempts could affect registrar reports or academic records, underscoring the importance of addressing this flaw promptly.
OpenCVE Enrichment