CVE-2026-1375
HIGHTutor LMS - IDOR
Title source: llmDescription
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3.9.5. This is due to missing object-level authorization checks in the `course_list_bulk_action()`, `bulk_delete_course()`, and `update_course_status()` functions. This makes it possible for authenticated attackers, with Tutor Instructor-level access and above, to modify or delete arbitrary courses they do not own by manipulating course IDs in bulk action requests.
Exploits (1)
References (5)
Scores
CVSS v3
8.1
EPSS
0.0002
EPSS Percentile
5.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-639
Status
published
Products (1)
themeum/Tutor LMS – eLearning and online course solution
< 3.9.5
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026