Description
The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Tutor LMS WordPress plugin versions before 3.9.13 fail to verify that a user has permission to edit a target post before performing an overwrite, authorizing requests only against an unrelated identifier. This flaw permits an authenticated instructor to overwrite any post or page on the site, regardless of ownership, effectively allowing content manipulation, deletion, or injection. The vulnerability represents an improper authorization flaw (CWE‑285) that compromises the integrity of site content.

Affected Systems

Tutor LMS, the WordPress plugin that provides learning management functionality, is affected by this issue in all releases earlier than version 3.9.13. The flaw is confined to the plugin itself and does not extend to core WordPress components; however, any site running an impacted version is at risk for unauthorized post modification.

Risk and Exploitability

The flaw can be exploited by a legitimate instructor through normal authenticated requests to the content‑builder save handler, with no additional prerequisites. The CVSS score of 6.5 indicates a medium‑severity integrity impact, while the EPSS score of <1% and absence from the CISA KEV catalog suggest a low likelihood of exploitation in the wild. An attacker would likely target the plugin’s web interface to trigger the unauthorized overwrite.

Generated by OpenCVE AI on August 4, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tutor LMS plugin to version 3.9.13 or later to receive the corrected authorization logic.
  • Limit instructor accounts to the least privilege needed, removing or revoking rights that allow site‑wide editing if not essential.
  • Configure or disable the plugin’s content‑builder functionality for posts and pages that are not owned by the instructor, ensuring ownership checks are enforced before allowing edits.

Generated by OpenCVE AI on August 4, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-639

Wed, 29 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-639

Sun, 26 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 22 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Fri, 17 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 13 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.
Title Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-13T15:48:20.554Z

Reserved: 2026-06-15T11:20:21.197Z

Link: CVE-2026-12274

cve-icon Vulnrichment

Updated: 2026-07-13T15:48:12.051Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:30:05Z

Weaknesses

No weakness.