WP Clinic
Entrar Registrarse

CVE

CVE-2026-1375 — Tutor LMS – eLearning and online course solution [tutor] < 3.9.6

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-1375 Tutor LMS – eLearning and online course solution [tutor] < 3.9.6 Desconocido < 3.9.6 3.9.6 0000-00-00

CVE-2026-1375

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3.9.5. This is due to missing object-level authorization checks in the `course_list_bulk_action()`, `bulk_delete_course()`, and `update_course_status()` functions. This makes it possible for authenticated attackers, with Tutor Instructor-level access and above, to modify or delete arbitrary courses they do not own by manipulating course IDs in bulk action requests.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.