CVE-2026-5502 is an authorization bypass vulnerability affecting the Tutor LMS plugin for WordPress through version 3.9.8. The flaw exists in the tutor_update_course_content_order() function, which performs CSRF validation but fails to verify user permissions when the 'content_parent' parameter is absent from requests. This allows authenticated subscribers and higher-level users to manipulate course content structure by detaching lessons from topics, moving lessons between topics, and reordering course materials without proper authorization checks. The vulnerability presents a medium-severity risk with a CVSS score of 5.3, characterized by network-based exploitation requiring no user interaction and low attack complexity. The primary impact is integrity compromise, as attackers can disrupt course organization and structure, though no confidentiality or availability damage is indicated. The attack requires only valid user authentication at the subscriber level or above, making it accessible to a broad potential threat actor pool. There is currently no evidence of active exploitation or public exploit code availability for this vulnerability. It does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on vendor hot lists. The EPSS score of 0.00014 indicates negligible probability of exploitation in the wild compared to other vulnerabilities, suggesting this remains primarily a theoretical risk at present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Themeum | Tutor LMS – ELearning And Online Course Solution | >= 0, <= 3.9.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.