Impact
The Tutor LMS WordPress plugin contains an Insecure Direct Object Reference flaw that fails to enforce per-object ownership checks on its course content type. Any user with the instructor role can read the content of private courses owned by other instructors, potentially disclosing confidential course material.
Affected Systems
The affected product is the Tutor LMS WordPress plugin. All installations running any version prior to 4.0.6 are susceptible; no specific patch level is provided beyond this version boundary.
Risk and Exploitability
The vulnerability can be exploited by any authenticated instructor through the web interface, as the plugin does not validate ownership of the requested course. The EPSS score is <1% and the CVSS score is 2.7, indicating low severity, and the vulnerability is not listed in the CISA KEV catalog. The low EPSS score indicates a low probability of exploitation. The likely attack vector is remote via the web application, requiring only instructor credentials.
OpenCVE Enrichment