
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23799 is a Missing Authorization (Broken Access Control) vulnerability in the Themeum Tutor LMS WordPress plugin, affecting versions up to and including 3.9.5. It allows low-privileged authenticated attackers (Subscriber-level) to exploit incorrectly configured access control security levels, potentially accessing sensitive data. The vulnerability was reported on November 26, 2025, and published on March 5, 2026, with a patched version (3.9.6) available. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing certain privileged actions. An authenticated attacker with Subscriber-level access can send crafted requests to trigger functionality intended for higher-privileged roles, bypassing access control checks. No complex preconditions are required beyond having a valid low-privilege account on the affected WordPress site. The vulnerability was discovered by security researcher Supakiad S. (m3ez) and reported through Patchstack (Patchstack).
Successful exploitation results in a high confidentiality impact, with no integrity or availability impact, as reflected in the CVSS score. An attacker with a low-privilege account (e.g., a student or subscriber on a Tutor LMS-powered e-learning site) could access sensitive information or perform actions reserved for instructors or administrators. The scope is limited to the affected WordPress installation, but exposure of course data, user information, or administrative functions could have significant consequences for site operators and their users (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.017%, indicating a low current probability of exploitation in the wild. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity. There is no current CISA KEV catalog listing for this CVE (Patchstack).
/wp-admin/admin-ajax.php or Tutor LMS REST API routes) that are not normally accessed by subscribers./wp-content/plugins/tutor/readme.txt).The vendor Themeum has released version 3.9.6 of the Tutor LMS plugin, which patches this vulnerability. Site administrators should update the plugin to version 3.9.6 or later immediately. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated, and auto-update for vulnerable plugins can be enabled through the Patchstack dashboard (Patchstack).
Sucuri included CVE-2026-23799 in their March 2026 vulnerability patch roundup, highlighting it as part of broader WordPress plugin security coverage (Sucuri Blog). The vulnerability received standard community attention via CVE tracking feeds and security aggregators, consistent with medium-severity WordPress plugin issues.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."