WordPress Plugin Vulnerabilities

Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR

Description

The plugin does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.

Proof of Concept

Affects Plugins

Fixed in 3.9.13

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes

Timeline

Publicly Published
2026-06-22 (about 1 month ago)
Added
2026-06-22 (about 1 month ago)
Last Updated
2026-06-22 (about 1 month ago)

Other