CVE-2026-3360Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authentication and authorization checks in the `pay_incomplete_order()` function. The function accepts an attacker-controlled `order_id` parameter and uses it to look up order data, then writes billing fields to the order owner's profile (`$order_data->user_id`) without verifying the requester's identity or ownership. Because the Tutor nonce (`_tutor_nonce`) is exposed on public frontend pages, this makes it possible for unauthenticated attackers to overwrite the billing profile (name, email, phone, address) of any user who has an incomplete manual order, by sending a crafted POST request with a guessed or enumerated `order_id`.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-19: 1Technical Details · 2026-04-10: 204-1004-1104-19
Signal classification2 categories
Disclosure
375.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure2
2026-04-111
Disclosure1
2026-04-191
PoC1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3360 Insecure Direct Object Reference in Tutor LMS Plugin for WordPress Up to 3.9.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3360

    Post summary

    The post announces a new vulnerability (CVE-2026-3360) in the Tutor LMS WordPress plugin, identifying it as an Insecure Direct Object Reference without providing PoC, exploit code, or mitigation details.

    0001142
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3360 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to, and including, 3.9… https://www.cve.org/CVERecord?id=CVE-2026-3360

    Post summary

    The CVE-2026-3360 vulnerability—an insecure direct object reference in Tutor LMS up to version 3.9—has been disclosed, with no mention of PoC, exploitation, or patch.

    00010128
    57.0K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-3360-tutor-version-3-9-7-high-vulnerability-proof-of-concept CVE-2026-3360 #WordPress plugin #vulnerability tutor #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post provides a link to a proof‑of‑concept for CVE‑2026‑3360 with no additional technical or exploitation details.

    0000055
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3360 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3360 #CVE-2026-3360 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/HhsP8x9veR

    Post summary

    The tweet announces the new CVE-2026-3360 for WordPress with a severity of 7.5, but does not provide technical details, PoC, patch information, or evidence of exploitation.

    0000054
    123 followersView on X

Explore more