CVE-2026-13443: Stored XSS in Tutor LMS WordPress Plugin (Lesson Attachment Title)
A security flaw in the Tutor LMS WordPress plugin allows authenticated users with author-level permissions or higher to embed malicious JavaScript code into lesson attachments. When other users view pages containing these attachments, the injected script executes in their browsers, potentially compromising their accounts or stealing sensitive data. The vulnerability affects all versions up to 3.9.13 and requires an authenticated attacker—this is not a zero-authentication threat, but poses real risk in multiuser WordPress environments where content creators may be compromised or malicious.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.4 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-01 / 2026-07-01
NVD description (verbatim)
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
8 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13443 is a Stored Cross-Site Scripting (XSS) vulnerability in Tutor LMS stemming from inadequate input sanitization and output escaping of the Lesson Attachment Title field. An authenticated user with author-level or administrative privileges can inject arbitrary JavaScript that persists in the database. The vulnerability has a CVSS v3.1 score of 6.4 (Medium severity) with a vector indicating network-accessible exploitation, low attack complexity, and requirement for low-privilege authentication. The injected payload executes in the context of any user who subsequently accesses the affected lesson page, potentially allowing session hijacking, credential theft, or malware distribution within the WordPress environment.
Business impact
Organizations relying on Tutor LMS for course delivery face reputational and operational risk if attackers compromise course content or student sessions. In educational and corporate training contexts, stored XSS can enable data exfiltration of student records, test answers, or completion certificates. The requirement for author-level access means the threat landscape includes compromised instructor accounts, disgruntled staff, or supply-chain compromise of plugin integrations. Depending on the sensitivity of course material and student data, incidents could trigger data protection compliance obligations (FERPA, GDPR, etc.) and erode institutional trust.
Affected systems
The vulnerability affects all versions of the Tutor LMS – eLearning and online course solution plugin for WordPress up to and including version 3.9.13. Any WordPress installation running this plugin with multiuser authorship capability (authors or admins creating lessons with attachments) is potentially vulnerable. The threat is highest in public or semi-public WordPress networks where author accounts are distributed among instructors, third-party consultants, or content partners.
Exploitability
Exploitation requires authentication—specifically author-level access or higher within WordPress. Attack complexity is low: an attacker simply crafts a lesson attachment with a malicious title containing JavaScript and waits for other users to access the lesson. No user interaction beyond normal course viewing is required for payload execution. The stored nature of the XSS means a single injection can compromise many users over time, making it attractive to motivated attackers with insider access or those who have compromised instructor accounts through phishing or credential stuffing.
Remediation
Update the Tutor LMS plugin to a patched version released after 2026-07-01. Verify the specific version number against the official plugin repository or vendor advisory. Until patching is possible, restrict author-level access to trusted personnel only, audit existing lesson attachments for suspicious titles containing script tags or encoded payloads, and consider temporarily disabling the lesson attachment feature if operationally feasible. Implement Content Security Policy (CSP) headers on your WordPress site to mitigate XSS payload execution.
Patch guidance
Check the official Tutor LMS plugin repository and the plugin developer's security advisories for patch availability. Update through the WordPress admin dashboard (Plugins > Updates) once a patched version is released. Before deploying to production, test the update in a staging environment to ensure compatibility with your course structure and any custom integrations. After patching, review lesson attachment titles from the period before the update to identify and remove any suspicious content.
Detection guidance
Audit lesson attachment titles for presence of HTML/JavaScript patterns such as <script>, onerror=, onclick=, or encoded variations (%3c, <, etc.). Review WordPress administrator and author activity logs for unusual lesson or attachment modifications. Monitor web application firewall (WAF) logs for POST requests to lesson endpoints containing script injection patterns. Query your WordPress database directly: examine the wp_posts and wp_postmeta tables for suspicious serialized data in lesson attachment metadata. Enable WordPress security plugins with XSS detection capabilities to flag existing or new malicious attachments.
Why prioritize this
Although rated MEDIUM in CVSS terms, prioritize remediation based on your WordPress user model: if multiple untrusted authors have access, this is higher risk. The stored nature of the XSS and broad audience reach (all course students) amplify impact. The vulnerability is not currently listed in CISA's KEV catalog, but its presence in a widely-used plugin warrants rapid assessment and patching in any educational or training deployment.
Risk score, explained
The CVSS 6.4 (Medium) score reflects the requirement for authentication (PR:L), lack of availability impact (A:N), but cross-site context (S:C) that can affect many users. If your WordPress instance has many authors or open registration, effective risk is higher than the base score suggests. The exploitability is straightforward and requires no special tools or knowledge—any author can craft a malicious title.
Frequently asked questions
Who can exploit this vulnerability?
Any user with WordPress author-level access or higher (editors, administrators). This includes staff, instructors, consultants, or third parties with content creation permissions. Attackers who compromise such accounts via phishing, weak passwords, or supply-chain methods can also exploit it.
What if we use a security plugin or Web Application Firewall?
Security plugins and WAF rules can detect and block some XSS patterns, but are not a substitute for patching. Configure your WAF to strip or escape HTML/JavaScript in lesson attachment metadata, and enable WordPress security plugins with XSS protection. However, update the plugin as soon as possible.
Do we need to notify users if this vulnerability was exploited?
If you discover evidence of malicious attachments being added, inspect logs to determine if user sessions were compromised. Depending on jurisdiction and data sensitivity, you may be required to notify affected users under GDPR, CCPA, or educational privacy laws. Consult legal and incident response teams if exploitation is confirmed.
Can this be exploited remotely without physical access?
Yes. Any user with network access to your WordPress login page and valid author-level credentials (or attackers who obtain them) can inject the payload. The attack is fully network-based and can originate from anywhere with internet connectivity.
This analysis is provided for informational purposes and does not constitute legal, compliance, or operational advice. No exploit code or weaponized proof-of-concept is included. Patch version numbers and availability must be verified against the official Tutor LMS vendor advisory and WordPress plugin repository. Organizations should validate all security recommendations in their own environment and consult with internal security, legal, and compliance teams before taking action. SECurity incidents involving this vulnerability should be reported to relevant authorities and affected parties in accordance with applicable law. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise
- CVE-2019-25739MEDIUMGigToDo 1.3 Stored XSS Vulnerability in Proposal Descriptions
- CVE-2019-25742MEDIUMStored XSS in Zoner Real Estate WordPress Theme 4.1.1 – Admin Account Compromise Risk
- CVE-2019-25743MEDIUMWordPress Soliloquy Lite 2.5.6 Stored XSS Vulnerability
- CVE-2019-25744MEDIUMWordPress Popup Builder 3.49 Stored XSS Vulnerability – Exploit Prevention & Patch Guide