CVE-2026-18439 | meum Tutor LMS Plugin up to 4.0.7 on WordPress AJAX Action handle_delete improper authorization

SecurityVulns

A vulnerability described as problematic has been identified in meum Tutor LMS Plugin up to 4.0.7 on WordPress. Affected by this vulnerability is the function QuizBuilder::save_questions/QuizBuilder::save_question_answers/QuizBuilder::handle_delete of the component AJAX Action. Executing a manipulation of the argument question_id/answer_id/deleted_question_ids/deleted_answer_ids can lead to improper authorization.

The identification of this vulnerability is CVE-2026-18439. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More