Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5502

21
FAUCET Score

CVE-2026-5502 is an authorization bypass vulnerability affecting the Tutor LMS plugin for WordPress through version 3.9.8. The flaw exists in the tutor_update_course_content_order() function, which performs CSRF validation but fails to verify user permissions when the 'content_parent' parameter is absent from requests. This allows authenticated subscribers and higher-level users to manipulate course content structure by detaching lessons from topics, moving lessons between topics, and reordering course materials without proper authorization checks. The vulnerability presents a medium-severity risk with a CVSS score of 5.3, characterized by network-based exploitation requiring no user interaction and low attack complexity. The primary impact is integrity compromise, as attackers can disrupt course organization and structure, though no confidentiality or availability damage is indicated. The attack requires only valid user authentication at the subscriber level or above, making it accessible to a broad potential threat actor pool. There is currently no evidence of active exploitation or public exploit code availability for this vulnerability. It does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on vendor hot lists. The EPSS score of 0.00014 indicates negligible probability of exploitation in the wild compared to other vulnerabilities, suggesting this remains primarily a theoretical risk at present.

Impacted Technologies

VendorProductVersion(s)CPE
ThemeumTutor LMS – ELearning And Online Course Solution
>= 0, <= 3.9.8CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 24th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/tutor/tags/3.9.7/classes/Course.php
plugins.trac.wordpress.org / browser/tutor/tags/3.9.7/classes/Course.php
plugins.trac.wordpress.org / browser/tutor/trunk/classes/Course.php
plugins.trac.wordpress.org / browser/tutor/trunk/classes/Course.php
plugins.trac.wordpress.org / changeset/3505142/tutor/tags/3.9.9/classes/Course.php
wordfence.com / threat-intel/vulnerabilities/id/f32ae42d-dd1f-41d7-8ae4-ddec56d78ae6