Tutor LMS WordPress Plugin Instructor-Level Arbitrary Post Overwrite Vulnerability

Vulnerability

A vulnerability exists in the Tutor LMS WordPress plugin in versions prior to 3.9.13. The issue arises because the plugin does not properly verify if a user has the right to edit a specific post before overwriting it in one of its content-builder save handlers. Instead, it only checks against an unrelated identifier. This flaw allows authenticated users with instructor-level access to overwrite and take control of any post or page on the site, including those owned by administrators.

Impact

Exploitation of this vulnerability allows for unauthorized overwriting and takeover of posts or pages, potentially leading to misuse of administrative content.

Remediation

Users are advised to update the Tutor LMS WordPress plugin to version 3.9.13 or later.

Added: Jul 13, 2026, 7:30 AM
Updated: Jul 13, 2026, 7:30 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.8
remediation
7.7
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.