Tutor LMS WordPress Plugin Quiz Attempt Modification Vulnerability

Vulnerability

A vulnerability exists in the Tutor LMS WordPress plugin in versions prior to 3.9.13, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts. The plugin fails to verify ownership of quiz attempts before writing to them, enabling users to overwrite recorded marks and pass/fail results. This issue arises from an Insecure Direct Object Reference (IDOR) vulnerability, where the ownership check can be bypassed by manipulating the request data.

Impact

Exploitation of this vulnerability allows for unauthorized modification of quiz attempt data, including overwriting marks and changing pass/fail results, potentially leading to improper assessment outcomes.

Reproduction

To reproduce this vulnerability, log in as a subscriber-level user who owns a quiz attempt. Obtain the Tutor nonce from the public course page. Then, send a request to the quiz endpoint, using the nonce and targeting a victim's quiz attempt by manipulating the attempt ID in the request. The victim's attempt will be force-completed and scored based on the attacker's actions, demonstrating the unauthorized modification of quiz data.

Remediation

Users are advised to update the Tutor LMS WordPress plugin to version 3.9.13 or later.

Added: Jul 13, 2026, 7:32 AM
Updated: Jul 13, 2026, 7:32 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.8
remediation
7.7
relevance
9.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.