Impact
The Tutor LMS plugin for WordPress lacks a proper authorization check for post deletion. Authenticated users with subscriber-level access or higher can trigger the lesson deletion handler, which internally calls wp_delete_post( $id, true ). This allows them to permanently remove arbitrary WordPress posts, including pages, courses, quizzes, and WooCommerce products, undermining content integrity and availability. The flaw is classified as an improper authorization vulnerability (CWE‑862).
Affected Systems
The Tutor LMS eLearning and online course solution plugin from themeum is affected in all versions up to and including 4.0.8. Users running the plugin at these versions are vulnerable; any installations of Tutor LMS 4.0.8 or earlier should be reviewed for remediation.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate severity. An EPSS score is not available, and the issue has not been listed in the CISA KEV catalog. Exploitation requires a multi‑step attack: the attacker must first upload a profile photo to create an attachment row, then create a Tutor topic linked to that attachment, and finally invoke the lesson deletion handler against any target post ID. The attacker must be authenticated as a subscriber or higher, which limits the pool of potential attackers but still permits abuse. The complexity of the chain reduces the likelihood of successful exploitation compared to a single‑step flaw, yet the potential for irreversible content loss warrants prompt remediation.
OpenCVE Enrichment