Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88944— Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter

Quick assessment

Affected
themeum Tutor LMS – eLearning and online course solution
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tutor LMS——一款 WordPress 电子学习与在线课程解决方案插件——在 4.0.8 及更早的所有版本中存在授权绕过(Authorization Bypass)漏洞。 该漏洞的成因是插件未能正确验证执行操作的用户是否具备相应权限。这使得拥有订阅者(subscriber)级别或更高权限的已认证攻击者能够通过调用 永久删除任意 WordPress 文章,包括页面、课程、测验以及 WooCommerce 产品。 利用此漏洞的攻击链要求攻击者首先触发个人资料照片上传流程,从而创建一个由攻击者作为作者(autho

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88944

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete arbitrary WordPress posts — including pages, courses, quizzes, and WooCommerce products — via wp_delete_post( $id, true ). The exploit chain requires the attacker to first trigger the profile-photo upload flow to obtain an authored wp_posts attachment row, then create a Tutor topic reparented to that attachment, before invoking the lesson deletion handler against any target post ID.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
themeum Tutor LMS – eLearning and online course solution 0 ~ 4.0.8 -

II. Public POCs for CVE-2026-88944

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88944

登录查看更多情报信息。

Other References for CVE-2026-88944 (9)

Same Patch Batch · themeum · 2026-09-19 · 3 CVEs total

CVE-2026-89333 6.5 MEDIUM Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensi
CVE-2026-89081 6.1 MEDIUM Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters

IV. Related Vulnerabilities

V. Comments for CVE-2026-88944

No comments yet


Leave a comment