PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-85571 Tutor LMS CVE debrief

CVE-2026-85571 Tutor LMS 4.0.5 - 4.1.0 Instructor+ Arbitrary Post Reparenting via IDOR allows unauthorized reassignment of post parents, potentially disrupting course content. The vulnerability exists in the Tutor LMS WordPress plugin before version 4.1.1, where course content ordering requests are not verified to belong to a course managed by the requester. This issue enables users with instructor level access to reassign the parent of any post on the site, affecting course content and learning materials.

Vendor
Tutor LMS
Product
Tutor LMS
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with Tutor LMS plugin versions 4.0.5 - 4.1.0 should assess exposure and prioritize patching. This includes reviewing the current version of Tutor LMS, applying patches if necessary, and monitoring for suspicious activity related to post reparenting. Additionally, defenders should consider restricting access to sensitive areas of the site and tracking exceptions and retesting remediated assets.

Why it matters

CVE-2026-85571 allows users with instructor level access to reassign the parent of any post on the site, potentially disrupting course content and learning materials. Defenders should prioritize verifying and patching Tutor LMS installations to prevent unauthorized post reparenting.

  • Potential unauthorized modification of course content
  • Possible disruption of learning materials and courses
  • Required verification of Tutor LMS version and application of patches
  • Potential impact on instructor and learner interactions with course materials

Technical summary

The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site. This vulnerability enables unauthorized reassignment of post parents, potentially disrupting course content and learning materials. Defenders should prioritize verifying and patching Tutor LMS installations to prevent unauthorized post reparenting and review compensating controls for exposed systems.

Defensive priority

Defenders should prioritize verifying and patching Tutor LMS installations to prevent unauthorized post reparenting.

Recommended defensive actions

  • Verify Tutor LMS version and apply patches if necessary
  • Restrict access to sensitive areas of the site
  • Monitor for suspicious activity related to post reparenting
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide limited information about the vulnerability, primarily focusing on the issue's existence and affected versions. Defenders should verify the Tutor LMS version and apply patches if necessary. The vulnerability allows users with instructor level access to reassign the parent of any post on the site, potentially disrupting course content and learning materials.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-85571 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-85571

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-85571 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85571

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.