Impact
Tutor LMS WordPress plugin versions before 3.9.13 fail to verify that a user has permission to edit a target post before performing an overwrite, authorizing requests only against an unrelated identifier. This flaw permits an authenticated instructor to overwrite any post or page on the site, regardless of ownership, effectively allowing content manipulation, deletion, or injection. The vulnerability represents an improper authorization flaw (CWE‑285) that compromises the integrity of site content.
Affected Systems
Tutor LMS, the WordPress plugin that provides learning management functionality, is affected by this issue in all releases earlier than version 3.9.13. The flaw is confined to the plugin itself and does not extend to core WordPress components; however, any site running an impacted version is at risk for unauthorized post modification.
Risk and Exploitability
The flaw can be exploited by a legitimate instructor through normal authenticated requests to the content‑builder save handler, with no additional prerequisites. The CVSS score of 6.5 indicates a medium‑severity integrity impact, while the EPSS score of <1% and absence from the CISA KEV catalog suggest a low likelihood of exploitation in the wild. An attacker would likely target the plugin’s web interface to trigger the unauthorized overwrite.
OpenCVE Enrichment