WordPress Plugin Vulnerabilities

Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection

Description

The plugin does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them.

Proof of Concept

Affects Plugins

Fixed in 4.0.0

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Sanjar Tulkinov
Submitter
Sanjar Tulkinov
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 18 days ago)
Added
2026-07-13 (about 17 days ago)
Last Updated
2026-07-22 (about 8 days ago)

Other