WordPress Plugin Vulnerabilities
Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
Description
The plugin does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
IDOR
OWASP top 10
CWE
Miscellaneous
Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-06-22 (about 1 month ago)
Added
2026-06-22 (about 1 month ago)
Last Updated
2026-06-22 (about 1 month ago)