CVE-2026-18439

CVE-2026-18439 published: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation that nested question_id...

View full NVD advisory → ← Back to CVE watch