CVE-2026-23799: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-23799 is a Missing Authorization (Broken Access Control) vulnerability in the Themeum Tutor LMS WordPress plugin, affecting versions up to and including 3.9.5. It allows low-privileged authenticated attackers (Subscriber-level) to exploit incorrectly configured access control security levels, potentially accessing sensitive data. The vulnerability was reported on November 26, 2025, and published on March 5, 2026, with a patched version (3.9.6) available. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing certain privileged actions. An authenticated attacker with Subscriber-level access can send crafted requests to trigger functionality intended for higher-privileged roles, bypassing access control checks. No complex preconditions are required beyond having a valid low-privilege account on the affected WordPress site. The vulnerability was discovered by security researcher Supakiad S. (m3ez) and reported through Patchstack (Patchstack).

Impact

Successful exploitation results in a high confidentiality impact, with no integrity or availability impact, as reflected in the CVSS score. An attacker with a low-privilege account (e.g., a student or subscriber on a Tutor LMS-powered e-learning site) could access sensitive information or perform actions reserved for instructors or administrators. The scope is limited to the affected WordPress installation, but exposure of course data, user information, or administrative functions could have significant consequences for site operators and their users (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.017%, indicating a low current probability of exploitation in the wild. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity. There is no current CISA KEV catalog listing for this CVE (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running Tutor LMS plugin version 3.9.5 or earlier using tools like WPScan or Shodan, or by checking the plugin version in publicly accessible readme files.
  2. Account Registration: Register or obtain a low-privilege account (Subscriber or Student level) on the target WordPress site.
  3. Identify Unprotected Endpoints: Enumerate Tutor LMS REST API endpoints or admin-ajax actions that lack proper authorization checks, targeting functionality intended for instructors or administrators.
  4. Craft Malicious Request: Send authenticated HTTP requests (with valid nonce/session cookies) to the identified privileged endpoints, bypassing the missing authorization check.
  5. Access Sensitive Data: Retrieve restricted course data, user information, or perform privileged actions that should be restricted to higher-privileged roles (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing repeated requests from low-privilege user accounts to Tutor LMS admin or instructor-level endpoints (e.g., /wp-admin/admin-ajax.php or Tutor LMS REST API routes) that are not normally accessed by subscribers.
  • Logs: Unusual patterns of authenticated requests from a single subscriber-level account accessing multiple restricted Tutor LMS functions in a short timeframe.
  • Network: Automated scanning traffic targeting WordPress sites with requests probing Tutor LMS plugin version information (e.g., /wp-content/plugins/tutor/readme.txt).

Mitigation and workarounds

The vendor Themeum has released version 3.9.6 of the Tutor LMS plugin, which patches this vulnerability. Site administrators should update the plugin to version 3.9.6 or later immediately. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated, and auto-update for vulnerable plugins can be enabled through the Patchstack dashboard (Patchstack).

Community reactions

Sucuri included CVE-2026-23799 in their March 2026 vulnerability patch roundup, highlighting it as part of broader WordPress plugin security coverage (Sucuri Blog). The vulnerability received standard community attention via CVE tracking feeds and security aggregators, consistent with medium-severity WordPress plugin issues.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management