Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter
Summary
| CVE | CVE-2026-18439 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-22 08:16:39 UTC |
| Updated | 2026-09-23 19:17:29 UTC |
| Description | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation that nested question_id, answer_id, deleted_question_ids[], and deleted_answer_ids[] values in the submitted payload belong to a quiz/topic/course the requester is authorized to manage. The handler only validates the top-level course_id, topic_id, and (when supplied) payload['ID'], but the nested identifiers are passed straight into $wpdb->update/DELETE statements in QuizBuilder::save_questions(), QuizBuilder::save_question_answers(), and QuizBuilder::handle_delete(). This makes it possible for authenticated attackers, with Instructor-level access and above, to overwrite the content and re-parent arbitrary quiz questions/answers belonging to other instructors or administrators, and to delete arbitrary quiz question and answer rows. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.002500000 probability, percentile 0.145130000 (date 2026-09-24)
Problem Types: CWE-639 | CWE-639 CWE-639 Authorization Bypass Through User-Controlled Key
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | DECLARED | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Themeum | Tutor LMS ELearning And Online Course Solution | affected 4.0.7 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| plugins.trac.wordpress.org/browser/tutor/tags/3.9.10/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/3.9.10/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/3.9.10/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/4.0.3/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| www.wordfence.com/threat-intel/vulnerabilities/id/6d07c82d-262a-4ac1-9ee5-7ef4d... | [email protected] | www.wordfence.com | |
| plugins.trac.wordpress.org/browser/tutor/tags/4.0.3/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/3.9.10/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/3.9.10/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/4.0.3/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/changeset/3690454/tutor/tags/4.0.8/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/4.0.3/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/tutor/tags/4.0.3/classes/QuizBuilder.php | [email protected] | plugins.trac.wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Nakul Chodha (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-07-30T20:38:30.000Z | Vendor Notified |
| CNA | 2026-09-21T18:52:22.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.