CVE-2026-89333: Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'studentid' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose the email address and Tutor profile phone number of arbitrary WordPress users, including Administrators, by iterating over user IDs via the studentid parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tutor LMS (WordPress plugin)to a version that resolves this vulnerability.Fixed in 4.0.8 - Compensating control
Restrict access to Tutor LMS endpoints/any pages or actions that accept the 'student_id' parameter to authorized roles only, limiting authenticated users who can reach the vulnerable functionality (subscriber-level and above) until upgraded.
- Operational
After upgrading, review any exposed user data (disclosed email addresses and Tutor profile phone numbers) and rotate/clean up any dependent data handling or notifications as needed.