Impact
The Tutor LMS plugin for WordPress contains an Authorization Bypass Through User‑Controlled Key flaw (CWE‑639) that allows an attacker to manipulate internal keys and retrieve or modify data that should be protected. This insecure direct object reference can expose course materials, student information, or instructor data, thereby compromising confidentiality and integrity of educational content on affected sites.
Affected Systems
WordPress installations running any version of the Tutor LMS plugin released by Themeum up to and including version 3.9.13 are affected. All earlier releases are also vulnerable because the flaw exists throughout the entire product line until patching in 3.9.14 or later.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is web‑based and requires a crafted HTTP request that manipulates user‑controlled key parameters within the plugin’s access‑control logic to bypass authorization.
OpenCVE Enrichment