CVE-2026-85571: Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR
The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Users with instructor-level access can exploit it. They can target posts outside courses they manage because the affected ordering requests do not verify course ownership.
What content can be affected?
An attacker can reassign the parent of any post on the site. This can let them take other instructors' course content into their own courses or make arbitrary published content unreachable.
Which versions should be remediated?
Tutor LMS versions before 4.1.1 are affected, including 4.0.5 through 4.1.0. Upgrade to 4.1.1 or later.