rootpwn

medium · CVSS v3 6.5 · EPSS 0.00269

CVE-2026-89333

The Tutor LMS plugin for WordPress contains an Insecure Direct Object Reference (IDOR) vulnerability in versions up to and including 4.0.8.

Overview

The Tutor LMS plugin for WordPress contains an Insecure Direct Object Reference (IDOR) vulnerability in versions up to and including 4.0.8. The flaw exists due to missing validation on the 'student_id' parameter. This allows authenticated attackers with subscriber-level access to harvest sensitive user information, including emails and phone numbers, by iterating through user IDs.

Description

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose the email address and Tutor profile phone number of arbitrary WordPress users, including Administrators, by iterating over user IDs via the student_id parameter.

Impact

This vulnerability impacts the confidentiality of user data within affected WordPress sites. Authenticated users with minimal privileges (subscriber-level) can systematically harvest email addresses and profile phone numbers of higher-privileged accounts, including Administrators. The integrity and availability of the system remain unaffected, but unauthorized information disclosure increases social engineering and credential stuffing risks.

Remediation

Update the Tutor LMS plugin to the latest patched version provided by the vendor once available. Review plugin access controls and restrict subscriber-level capabilities if necessary. Monitor web server access logs for anomalous, high-frequency requests targeting user profile endpoints or incrementing the 'student_id' parameter.

Risk context

Rated as medium severity with a CVSS v3 score of 6.5, the vulnerability requires authenticated access, which lowers immediate external exposure. The current EPSS score of 0.00269 indicates a low observed probability of exploitation in the wild, but defenders should prioritize patching to protect user PII.

Affected products

  • WordPress Tutor LMS plugin <= 4.0.8

Scores

Severity
medium
CVSS v2
6.8
CVSS v3
6.5
CVSS v4
EPSS
0.00269

WordPress Tutor LMS IDOR Information Disclosure Plug-in Vulnerability PII Leak

← All CVEs