CVE-2026-85571
Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.
| Vendor | unknown |
| Product | tutor lms |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown tutor lms
Be the first to know when new unknown vulnerabilities affecting unknown tutor lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Tutor LMS
4.0.5 < 4.1.1
References
Credits
vuxvinh WPScan