CVE · Medium

CVE-2026-6965 — Tutor LMS – eLearning and online course solution [tutor] < 3.9.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6965 Tutor LMS – eLearning and online course solution [tutor] < 3.9.10 Authorization Bypass Through User-Controlled Key Medium 5.3 < 3.9.10 3.9.10 2026-05-12

CVE-2026-6965

The Tutor LMS plugin for WordPress contains a security flaw that allows attackers with instructor-level access to manipulate course content they shouldn't be able to touch. This is because the `get_course_id_by()` function doesn't properly verify user input when determining course ownership, allowing an attacker to specify which course's content they want to tamper with. As a result, instructors can delete or modify courses and content belonging to other teachers, as well as manipulate student grades and access unpublished materials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.