Skip to main content
Vulnerability Database/CVE-2026-88944

CVE-2026-88944: Tutor LMS Authorization Bypass Vulnerability

CVE-2026-88944 is an authorization bypass flaw in Tutor LMS for WordPress that lets authenticated attackers delete arbitrary posts including courses and products. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-88944 Overview

CVE-2026-88944 is an authorization bypass vulnerability in the Tutor LMS – eLearning and online course solution plugin for WordPress. The flaw affects all versions up to and including 4.0.8. The plugin fails to properly verify user authorization before executing a lesson deletion handler that calls wp_delete_post( $id, true ). Authenticated attackers with subscriber-level access can permanently delete arbitrary WordPress posts, including pages, courses, quizzes, and WooCommerce products. Exploitation requires chaining the profile-photo upload flow with a crafted Tutor topic reparented to the resulting attachment before invoking the deletion handler against any target post ID. The issue is tracked under CWE-862: Missing Authorization.

Critical Impact

Any authenticated subscriber can permanently delete arbitrary content across the site, including revenue-generating WooCommerce products and instructional courses.

Affected Products

  • Tutor LMS – eLearning and online course solution plugin for WordPress, all versions ≤ 4.0.8
  • WordPress sites using Tutor LMS with WooCommerce integration
  • WordPress sites permitting subscriber-level user registration with the plugin active

Discovery Timeline

  • 2026-09-19 - CVE-2026-88944 published to the National Vulnerability Database
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-88944

Vulnerability Analysis

The vulnerability resides in the Tutor LMS lesson deletion handler. The handler invokes wp_delete_post( $id, true ) on a user-supplied post identifier without confirming that the requester owns the target post or holds a role authorized to delete it. Because the second argument is true, deletions bypass the WordPress trash and are permanent. The handler validates only that the caller can act on an intermediate Tutor topic, not the final target post ID. Referenced source locations include classes/Lesson.php line 541, classes/Course.php lines 1758 and 2055, and classes/Utils.php lines 3277, 7481, and 7666 in the 4.0.7 tag on the WordPress plugin repository.

Root Cause

The root cause is missing authorization ([CWE-862]) on the deletion endpoint. Ownership checks operate on the wrong object in the parent-child hierarchy. The handler trusts the reparenting relationship between a Tutor topic and its declared parent instead of independently validating capability against the post being deleted.

Attack Vector

The attack requires an authenticated account with subscriber privileges or higher. The exploit chain proceeds in three stages. First, the attacker triggers the profile-photo upload flow to create an attachment row in wp_posts authored by the attacker. Second, the attacker creates a Tutor topic and reparents it to that attachment, establishing an ownership relationship the plugin will honor. Third, the attacker calls the lesson deletion handler with the target post ID, which the plugin passes to wp_delete_post with force-delete enabled. The target may be any post type, including pages, courses, quizzes, and WooCommerce products. See the Wordfence vulnerability report for additional analysis.

Detection Methods for CVE-2026-88944

Indicators of Compromise

  • Unexpected entries in the WordPress audit log showing subscriber accounts deleting posts, pages, or WooCommerce products.
  • Newly created attachment rows in wp_posts authored by low-privilege accounts, immediately followed by Tutor topic creation.
  • Missing published content that cannot be recovered from the trash, indicating force-delete was used.
  • Sudden spikes in admin-ajax.php or Tutor LMS REST endpoint traffic from subscriber sessions.

Detection Strategies

  • Enable a WordPress activity logging plugin to record every wp_delete_post invocation with the acting user ID and target post type.
  • Alert on any deletion of a WooCommerce product, page, or course originating from a non-editor, non-administrator role.
  • Correlate profile-photo upload events, Tutor topic creation, and lesson deletion requests within short time windows to surface the exploit chain.

Monitoring Recommendations

  • Monitor web server logs for POST requests to Tutor LMS lesson deletion AJAX or REST routes originating from subscriber sessions.
  • Track database write patterns against wp_posts for high-volume DELETE operations tied to low-privilege session cookies.
  • Ingest WordPress and web server telemetry into a centralized logging platform for cross-source correlation and retention.

How to Mitigate CVE-2026-88944

Immediate Actions Required

  • Update the Tutor LMS plugin to a patched release above 4.0.8 as soon as the vendor makes it available.
  • Audit registered user accounts and remove or downgrade any unexpected subscriber-level accounts.
  • Take a full site backup, including the database and wp-content/uploads, before applying changes so deleted content can be restored.
  • Review recent deletions of pages, courses, quizzes, and WooCommerce products for evidence of exploitation.

Patch Information

The vendor committed a fix in changeset 3700174 in the Tutor LMS repository. Administrators should upgrade to the first stable Tutor LMS release that includes this changeset. Confirm the running version in the WordPress plugins page after upgrading.

Workarounds

  • Disable open user registration or set the default registration role to a value that cannot access Tutor LMS endpoints until patched.
  • Deactivate the Tutor LMS plugin if the site does not require it during the remediation window.
  • Deploy a web application firewall rule that blocks requests to Tutor LMS lesson deletion endpoints from users lacking editor or administrator capabilities.
  • Restrict access to admin-ajax.php Tutor actions using server-level IP allowlists for administrative networks where feasible.
bash
# Disable open registration and restrict default role via wp-config.php or Settings > General
wp option update users_can_register 0
wp option update default_role 'subscriber'

# Deactivate the plugin until a fixed release is installed
wp plugin deactivate tutor

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.