CVE-2026-18439 Overview
CVE-2026-18439 is an Insecure Direct Object Reference (IDOR) vulnerability [CWE-639] in the Tutor LMS – eLearning and online course solution plugin for WordPress. The flaw affects all versions up to and including 4.0.7. The vulnerable code path is the tutor_quiz_builder_save AJAX action, which fails to validate that nested identifiers in the submitted payload belong to a quiz, topic, or course the requester is authorized to manage.
Authenticated attackers with Instructor-level access or above can overwrite quiz questions and answers belonging to other instructors or administrators. They can also delete arbitrary quiz question and answer rows across the site.
Critical Impact
Instructor-level accounts can tamper with or delete quiz content owned by other users, undermining the integrity of course assessments across the platform.
Affected Products
- Tutor LMS – eLearning and online course solution plugin for WordPress, versions up to and including 4.0.7
- WordPress sites running Tutor LMS with Instructor-level (or higher) user registration enabled
- Multi-instructor Tutor LMS deployments where quiz ownership boundaries matter
Discovery Timeline
- 2026-09-22 - CVE-2026-18439 published to NVD
- 2026-09-23 - Last updated in NVD database
- Patch reference - Fix committed in Tutor LMS 4.0.8 via changeset 3690454 in the WordPress plugin repository
Technical Details for CVE-2026-18439
Vulnerability Analysis
The vulnerability resides in the QuizBuilder class handling of the tutor_quiz_builder_save AJAX action. When a request is received, the handler performs authorization checks only on the top-level course_id, topic_id, and, when supplied, payload['ID'] values. Nested identifiers within the payload are trusted implicitly.
Those nested identifiers include question_id, answer_id, deleted_question_ids[], and deleted_answer_ids[]. They are passed directly into $wpdb->update and DELETE statements within QuizBuilder::save_questions(), QuizBuilder::save_question_answers(), and QuizBuilder::handle_delete(). Because ownership is never re-checked at the row level, an attacker can supply identifiers belonging to quizzes owned by other instructors or administrators.
The result is arbitrary modification and deletion of quiz questions and answers across the site. Content confidentiality is not affected, but integrity of assessment data is compromised.
Root Cause
The root cause is missing object-level authorization on nested identifiers submitted to a bulk save endpoint. The handler assumes that valid top-level course_id and topic_id values imply the caller owns every child record referenced in the payload. This is a classic IDOR pattern where server-side code performs a coarse authorization check and then trusts client-supplied primary keys for downstream database writes.
Attack Vector
An authenticated user with Instructor privileges submits a crafted request to the tutor_quiz_builder_save AJAX endpoint. The request specifies a course_id and topic_id the attacker legitimately owns, but embeds question_id or answer_id values that belong to another instructor's quiz. The nested identifiers are consumed by QuizBuilder::save_questions() and QuizBuilder::save_question_answers(), which issue $wpdb->update statements that overwrite the victim rows. Supplying values in deleted_question_ids[] or deleted_answer_ids[] triggers QuizBuilder::handle_delete() and removes the referenced rows entirely.
See the affected functions in the plugin source at WordPress Tutor QuizBuilder Line 156, Line 291, and Line 781.
Detection Methods for CVE-2026-18439
Indicators of Compromise
- Unexpected modifications to wp_tutor_quiz_questions or wp_tutor_quiz_question_answers rows attributed to instructors who do not own the parent quiz.
- Unexplained deletions of quiz question or answer records outside of scheduled course maintenance windows.
- Instructor accounts issuing high volumes of POST requests to admin-ajax.php with action=tutor_quiz_builder_save.
Detection Strategies
- Correlate WordPress user IDs in web access logs with quiz ownership metadata. Flag tutor_quiz_builder_save calls where nested question_id or answer_id values map to quizzes owned by a different user.
- Enable database audit logging on Tutor LMS quiz tables and alert on UPDATE or DELETE statements originating from unexpected instructor sessions.
- Monitor for requests whose deleted_question_ids[] or deleted_answer_ids[] arrays exceed normal instructor editing behavior.
Monitoring Recommendations
- Retain WordPress and web server access logs for at least 90 days to support retrospective ownership analysis.
- Alert on new or newly-elevated Instructor-role accounts and review their initial quiz-editing activity.
- Baseline typical volumes of tutor_quiz_builder_save calls per instructor and alert on statistical outliers.
How to Mitigate CVE-2026-18439
Immediate Actions Required
- Upgrade the Tutor LMS plugin to version 4.0.8 or later, which contains the fix delivered in changeset 3690454.
- Audit Instructor-role accounts and revoke access for any that are unused, unrecognized, or suspicious.
- Review the Tutor LMS quiz tables for recent unexplained changes and restore from backup where tampering is confirmed.
Patch Information
The vendor fixed the vulnerability in Tutor LMS 4.0.8. The patch adds ownership validation for nested identifiers processed by QuizBuilder::save_questions(), QuizBuilder::save_question_answers(), and QuizBuilder::handle_delete(). Review the patch diff in the WordPress plugin changeset and the Wordfence Vulnerability Report for additional context.
Workarounds
- Temporarily restrict quiz-editing capabilities to trusted administrator accounts until the patch is applied.
- Disable open registration for Instructor-level accounts on affected sites.
- Apply a Web Application Firewall (WAF) rule to block tutor_quiz_builder_save requests that reference question_id or answer_id values inconsistent with the caller's owned quizzes.
# Example WP-CLI command to update the plugin
wp plugin update tutor --version=4.0.8
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.