Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3360

27
FAUCET Score

OVERVIEW CVE-2026-3360 is an Insecure Direct Object Reference vulnerability affecting the Tutor LMS eLearning plugin for WordPress in all versions up to 3.9.7. The flaw exists in the pay_incomplete_order() function, which fails to properly validate user authentication and authorization before allowing attackers to modify billing profile information for any user with an incomplete manual order. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 (HIGH), reflecting a network-accessible attack vector that requires no authentication, no special conditions, and no user interaction. The primary impact is integrity compromise, as attackers can overwrite billing fields including name, email, phone, and address for affected users. The attack is particularly feasible because the required Tutor nonce is publicly exposed on frontend pages, enabling unauthenticated attackers to craft successful requests using guessed or enumerated order IDs. EXPLOITATION STATUS Active exploitation of this vulnerability is not currently documented. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog, and no public exploit code or significant community attention has been reported. However, the low technical barrier to exploitation and public availability of the vulnerable plugin warrant close monitoring and prompt patching.

Impacted Technologies

VendorProductVersion(s)CPE
ThemeumTutor LMS – ELearning And Online Course Solution
>= 0, <= 3.9.7CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 22nd percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/tutor/tags/3.9.7/classes/Tutor.php
plugins.trac.wordpress.org / browser/tutor/tags/3.9.7/ecommerce/CheckoutController.php
plugins.trac.wordpress.org / browser/tutor/tags/3.9.7/ecommerce/CheckoutController.php
plugins.trac.wordpress.org / browser/tutor/trunk/ecommerce/CheckoutController.php
plugins.trac.wordpress.org / changeset/3496394/tutor/trunk/ecommerce/CheckoutController.php
wordfence.com / threat-intel/vulnerabilities/id/7f365519-dd0a-4f39-880d-7216ce2f7d1e