CVE-2026-6965
The Tutor LMS plugin for WordPress contains a security flaw that allows attackers with instructor-level access to manipulate course content they shouldn't be able to touch. This is because the `get_course_id_by()` function doesn't properly verify user input when determining course ownership, allowing an attacker to specify which course's content they want to tamper with. As a result, instructors can delete or modify courses and content belonging to other teachers, as well as manipulate student grades and access unpublished materials.
Based on public CVE data (MITRE/NVD).