CVE-2026-5502Disclosure

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_course_content_order() function. The function only validates the nonce (CSRF protection) but does not verify whether the user has permission to manage course content. The can_user_manage() authorization check only executes when the 'content_parent' parameter is present in the request. When this parameter is omitted, the function proceeds directly to save_course_content_order() which manipulates the wp_posts table without any authorization validation. This makes it possible for authenticated attackers with subscriber-level access and above to detach all lessons from any topic, move lessons between topics, and modify the menu_order of course content, effectively allowing them to disrupt the structure of any course on the site.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-17); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-17: 3Mentions · 2026-05-28: 1PoC Mentioned / Linked · 2026-04-17: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-04-17: 2Technical Details · 2026-05-28: 104-1705-28
Signal classification4 categories
Disclosure
125.0%
General
125.0%
PoC
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-173
Disclosure1General1PoC1
2026-05-281
Patch1
Full discourse4 posts
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-4911, CVE-2026-5502, CVE-2026-1108: CISA KEV Alert — Analysis, Detecti… "CISA adds critical RCE and privilege escalation flaws in Fortinet, Progress Software, and…" 🔗 https://securityarsenal.com/blog/cve-2026-4911-cve-2026-5502-cve-2026-1108-cisa-kev-alert-analysis-detection-and-patching #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The post reports a CISA KEV alert for three critical CVEs involving RCE and privilege escalation in Fortinet and Progress Software, highlighting detection and recommended patches.

    0000064
    16 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-5502-tutor-version-3-9-8-medium-vulnerability-proof-of-concept CVE-2026-5502 #WordPress plugin #vulnerability tutor #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for CVE‑2026‑5502 in the Tutor WordPress plugin is shared via a link; no exploit code, active attacks, patches, or detailed technical data are discussed.

    0000055
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5502 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.… https://www.cve.org/CVERecord?id=CVE-2026-5502

    Post summary

    The text announces CVE-2026-5502 as a vulnerability in Tutor LMS that permits unauthorized manipulation of course content in affected versions, with no PoC, exploit, or patch information provided.

    0000068
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5502 Unauthorized Course Content Manipulation in Tutor LMS Plugin for WordPress 3.9.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5502

    Post summary

    The snippet lists CVE-2026-5502, describing an unauthorized course content manipulation issue in Tutor LMS 3.9.8 and links to a vulnerability database entry for more information.

    0000038
    4.0K followersView on X

Explore more