๐Ÿ” CVE Alert

CVE-2026-85571

UNKNOWN 0.0

Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.

Vendor unknown
Product tutor lms
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown tutor lms

Be the first to know when new unknown vulnerabilities affecting unknown tutor lms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Tutor LMS
4.0.5 < 4.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3c4ce27a-527a-416f-b1c8-d40ca5f65974/

Credits

vuxvinh WPScan