CVE-2026-3358Disclosure

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, 3.9.7. This is due to missing post_status validation in the `enroll_now()` and `course_enrollment()` functions. Both enrollment endpoints verify the nonce, user authentication, and whether the course is purchasable, but fail to check if the course has a `private` post_status. This makes it possible for authenticated attackers with Subscriber-level access or above to enroll in private courses by sending a crafted POST request with the target course ID. The enrollment record is created in the database and the private course title and enrollment status are exposed in the subscriber's dashboard, though WordPress core access control prevents the subscriber from viewing the actual course content (returns 404). Enrollment in private courses should be restricted to users with the `read_private_posts` capability.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-11: 2Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-18: 1Technical Details · 2026-04-11: 104-1104-18
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-112
Disclosure1General1
2026-04-181
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-3358-tutor-version-3-9-7-medium-vulnerability-proof-of-concept CVE-2026-3358 #WordPress plugin #vulnerability tutor #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The message announces the availability of a proof‑of‑concept for CVE‑2026‑3358 targeting the WordPress Tutor plugin (v3.9.7), but offers no detailed exploit technique, patch information, or evidence of active exploitation.

    0000045
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3358 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, … https://www.cve.org/CVERecord?id=CVE-2026-3358

    Post summary

    The statement discloses that Tutor LMS WordPress plugin is vulnerable to unauthorized private course enrollment across all versions, without mentioning PoC, exploit tools, active attacks, or patch details.

    00000143
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3358 Unauthorized Private Course Enrollment in Tutor LMS Plugin Versions Up to 3.9.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3358

    Post summary

    The resource reports CVE‑2026‑3358, which permits unauthorized enrollment in private courses in Tutor LMS plugin versions up to 3.9.7.

    0000040
    4.0K followersView on X

Explore more