CVE-2026-1375: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1375 is an Insecure Direct Object Reference (IDOR) vulnerability in the Tutor LMS – eLearning and online course solution plugin for WordPress, affecting all versions up to and including 3.9.5. The flaw allows authenticated attackers with Tutor Instructor-level access or higher to modify or delete arbitrary courses they do not own by manipulating course IDs in bulk action requests. It was published on February 3, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is missing object-level authorization checks (CWE-639: Authorization Bypass Through User-Controlled Key) in three functions within classes/Course_List.php: course_list_bulk_action(), bulk_delete_course(), and update_course_status(). These functions accept user-supplied course IDs in bulk action requests without verifying whether the requesting instructor owns the targeted courses, allowing any instructor to target courses belonging to other users. An attacker can craft HTTP requests with arbitrary course IDs to trigger unauthorized modifications or deletions (Wordfence, WordPress Trac).

Impact

Successful exploitation allows authenticated instructors to modify the content or status of any course on the platform, or permanently delete courses they do not own, resulting in high integrity and high availability impact. This could disrupt eLearning operations, destroy course content created by other instructors or administrators, and undermine platform trust. There is no confidentiality impact, as the vulnerability does not expose sensitive data (Wordfence).

Exploitability

A public proof-of-concept exploit has been published on GitHub (github.com/d3kc4rt1/CVE-2026-1375) and referenced via Sploitus (PacketStorm:218672), indicating the vulnerability has been weaponized to some degree. No confirmed in-the-wild exploitation or threat actor attribution has been reported at this time. The EPSS score is approximately 0.041%, reflecting a currently low but non-zero probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid Tutor Instructor-level account, limiting the attack surface to authenticated users (Wordfence, Sploitus).

Exploitation steps

  1. Obtain Instructor Access: Register or compromise a Tutor Instructor-level account on the target WordPress site running Tutor LMS ≤ 3.9.5.
  2. Enumerate Course IDs: Browse the platform or use authenticated requests to enumerate valid course IDs belonging to other instructors or administrators (course IDs are typically sequential integers).
  3. Craft Bulk Action Request: Construct an HTTP POST request targeting the course management endpoint (e.g., the admin-ajax or course list handler) that invokes course_list_bulk_action(), bulk_delete_course(), or update_course_status(), substituting the attacker's own course IDs with the target course IDs.
  4. Submit Unauthorized Request: Send the crafted request with the manipulated course IDs. Because no ownership check is performed, the server processes the action against the targeted courses.
  5. Achieve Objective: The attacker successfully modifies course status, alters course content, or permanently deletes courses owned by other users (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to course management or admin-ajax endpoints with bulk action parameters containing course IDs not associated with the authenticated instructor's own courses; repeated bulk action requests from a single instructor account targeting multiple course IDs in rapid succession.
  • Application: Unexpected course status changes (e.g., published → draft, or vice versa) or course deletions not initiated by the course owner; audit log entries (if enabled) showing bulk operations performed by instructor accounts on courses they do not own.
  • Network: Unusual volume of bulk action HTTP POST requests from a single authenticated session targeting the Tutor LMS course management endpoint.

Mitigation and workarounds

Users should update the Tutor LMS plugin to a version higher than 3.9.5, which includes the fix adding ownership verification in the affected functions (see the patch changeset on WordPress Trac). As an interim measure, restrict Tutor Instructor-level access to fully trusted users only, and review existing instructor accounts for unauthorized activity. Enabling WordPress activity/audit logging can help detect unauthorized bulk course operations. Network-level monitoring for anomalous bulk action requests to course management endpoints is also recommended (Wordfence, WordPress Trac).

Community reactions

Wordfence published the vulnerability in their weekly WordPress vulnerability report for February 2–8, 2026, and it was included in the CISA vulnerability bulletin for the week of February 2, 2026. The vulnerability was also picked up by security aggregators including Qualys (detection ID 530911), VulDB, Vulners, and INCIBE-CERT. No significant independent researcher commentary or notable social media discussion beyond standard aggregation has been observed (Wordfence Blog, CISA Bulletin).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management