---
id: CVE-2026-85569
title: >-
  The Tutor LMS  WordPress plugin before 4.0.8 does not correctly determine
  whether an incoming request is addressed to its own REST API, and does not
  enforce the permission recorded against an API credential, allowing the holder
  of a read…
summary: >-
  The Tutor LMS  WordPress plugin before 4.0.8 does not correctly determine
  whether an incoming request is addressed to its own REST API, and does not
  enforce the permission recorded against an API credential, allowing the holder
  of a read…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
product: Tutor LMS
affected:
  - tutor_lms >= 2.7.1 < 4.0.8
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:51.123'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85569'
references:
  - url: 'https://wpscan.com/vulnerability/ddbae988-37a2-4fb7-a813-bbc708f1f1c9/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:19:07.895470Z'
epss: 0.0043
epssPercentile: 0.36852
ingestedAt: '2026-09-16T06:51:06.251Z'
---

## Overview

The Tutor LMS  WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not enforce the permission recorded against an API credential, allowing the holder of a read-only key to act as the administrator account that issued it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
