Description
The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.3 due to missing validation on a user controlled key when viewing and editing assignments through the tutor_assignment_submit() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and edit assignment submissions of other students.
Problem types
CWE-285 Improper Authorization
Product status
* (semver)
Timeline
| 2025-08-01: | Vendor Notified |
| 2025-10-24: | Disclosed |
Credits
Sergio Framiñánn García
References
www.wordfence.com/...-3c2e-43e2-82a0-b742276b9640?source=cve