OVERVIEW CVE-2026-3360 is an Insecure Direct Object Reference vulnerability affecting the Tutor LMS eLearning plugin for WordPress in all versions up to 3.9.7. The flaw exists in the pay_incomplete_order() function, which fails to properly validate user authentication and authorization before allowing attackers to modify billing profile information for any user with an incomplete manual order. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 (HIGH), reflecting a network-accessible attack vector that requires no authentication, no special conditions, and no user interaction. The primary impact is integrity compromise, as attackers can overwrite billing fields including name, email, phone, and address for affected users. The attack is particularly feasible because the required Tutor nonce is publicly exposed on frontend pages, enabling unauthenticated attackers to craft successful requests using guessed or enumerated order IDs. EXPLOITATION STATUS Active exploitation of this vulnerability is not currently documented. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog, and no public exploit code or significant community attention has been reported. However, the low technical barrier to exploitation and public availability of the vulnerable plugin warrant close monitoring and prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Themeum | Tutor LMS – ELearning And Online Course Solution | >= 0, <= 3.9.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.