Description
The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not enforce the permission recorded against an API credential, allowing the holder of a read-only key to act as the administrator account that issued it.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Read‑Only API Key
Action: Immediate Patch
AI Analysis

Impact

The Tutor LMS WordPress plugin, in all releases prior to 4.0.8, fails to classify incoming REST requests as originating from the plugin’s own API. Because of this misclassification, the plugin does not enforce the permissions attached to an API credential, allowing a user with a read‑only key to perform actions with administrator privileges. The flaw resides in improper access control over API endpoints, providing unrestricted escalation of privileges.

Affected Systems

Any WordPress installation that has the Tutor LMS plugin installed at a version older than 4.0.8 is affected, regardless of the WordPress core version. Administrators or developers who rely on the plugin’s read‑only keys to restrict instructor access are exposed to this risk.

Risk and Exploitability

The vulnerability is exploitable remotely through the REST API and requires only possession of a read‑only key. Once an attacker submits a request that the plugin misclassifies as internal, they gain full administrator capabilities. The EPSS score is below 1 % and the flaw is not listed in CISA’s KEV catalog, suggesting limited active exploitation to date. Nevertheless, the ability to gain complete administrative control makes the risk severity high, and a typical CVSS assessment would rate it as a severe or critical issue.

Generated by OpenCVE AI on September 16, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tutor LMS plugin to version 4.0.8 or later so that it correctly verifies REST request origins and enforces API credential permissions.
  • After updating, audit any read‑only API keys used on the site; revoke or regenerate them with the minimal required scopes to avoid granting excessive privileges.
  • As an interim measure before upgrading, consider disabling the plugin’s read‑only API feature or reducing key privileges to the bare minimum while monitoring for unusual REST activity.

Generated by OpenCVE AI on September 16, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not enforce the permission recorded against an API credential, allowing the holder of a read-only key to act as the administrator account that issued it.
Title Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-16T06:00:14.474Z

Reserved: 2026-09-04T10:45:46.193Z

Link: CVE-2026-85569

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:34.217

Modified: 2026-09-16T20:25:29.240

Link: CVE-2026-85569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T16:30:08Z

Weaknesses