PatchSiren cyber security CVE debrief
CVE-2026-85571 Tutor LMS CVE debrief
CVE-2026-85571 Tutor LMS 4.0.5 - 4.1.0 Instructor+ Arbitrary Post Reparenting via IDOR allows unauthorized reassignment of post parents, potentially disrupting course content. The vulnerability exists in the Tutor LMS WordPress plugin before version 4.1.1, where course content ordering requests are not verified to belong to a course managed by the requester. This issue enables users with instructor level access to reassign the parent of any post on the site, affecting course content and learning materials.
- Vendor
- Tutor LMS
- Product
- Tutor LMS
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with Tutor LMS plugin versions 4.0.5 - 4.1.0 should assess exposure and prioritize patching. This includes reviewing the current version of Tutor LMS, applying patches if necessary, and monitoring for suspicious activity related to post reparenting. Additionally, defenders should consider restricting access to sensitive areas of the site and tracking exceptions and retesting remediated assets.
Why it matters
CVE-2026-85571 allows users with instructor level access to reassign the parent of any post on the site, potentially disrupting course content and learning materials. Defenders should prioritize verifying and patching Tutor LMS installations to prevent unauthorized post reparenting.
- Potential unauthorized modification of course content
- Possible disruption of learning materials and courses
- Required verification of Tutor LMS version and application of patches
- Potential impact on instructor and learner interactions with course materials
Technical summary
The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site. This vulnerability enables unauthorized reassignment of post parents, potentially disrupting course content and learning materials. Defenders should prioritize verifying and patching Tutor LMS installations to prevent unauthorized post reparenting and review compensating controls for exposed systems.
Defensive priority
Defenders should prioritize verifying and patching Tutor LMS installations to prevent unauthorized post reparenting.
Recommended defensive actions
- Verify Tutor LMS version and apply patches if necessary
- Restrict access to sensitive areas of the site
- Monitor for suspicious activity related to post reparenting
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide limited information about the vulnerability, primarily focusing on the issue's existence and affected versions. Defenders should verify the Tutor LMS version and apply patches if necessary. The vulnerability allows users with instructor level access to reassign the parent of any post on the site, potentially disrupting course content and learning materials.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85571 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85571
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85571 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85571
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/85xxx/CVE-2026-85571.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/3c4ce27a-527a-416f-b1c8-d40ca5f65974/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.