CVE-2026-57694

WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.


We have discovered 8,507 live websites that are affected by CVE-2026-57694.

Run a Free Instant Scan




Affected Software

Product  Tutor LMS
Category Learning Management System
Vulnerable Domains8,507 live websites (96% of Tutor LMS install base)
Vulnerable Versions
  • from 0 through 3.9.13
Vulnerable Versions Count125 versions ( 98% of all versions)



Details

  • Published - Jul 13, 2026
  • Updated - Jul 13, 2026

Credits

  • TristanInSec | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-57694
United States2,376 websites



Germany650 websites
Poland431 websites
Cyprus425 websites
France416 websites
India397 websites
GB372 websites
Brazil320 websites
Spain249 websites
Italy231 websites

Website Distribution by TLD

Number of websites using CVE-2026-57694
.com3,956 websites
.org538 websites
.pl339 websites
.com.br283 websites
.de195 websites
.net174 websites
.it162 websites
.fr145 websites
.co.uk138 websites
.nl114 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-57694

Top websites that are affected by CVE-2026-57694. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*****************.com GB**,***
***************.org United States**,***
*************.org United States**,***
*****.com France***,***
**************.com Spain***,***
***********.com ***,***
*********.es Spain***,***
****************.com United States***,***
*****.es Spain***,***
See full domain list

FAQ

A total of 8,507 websites have been identified as vulnerable to CVE-2026-57694, based on global website indexing conducted by WebTechSurvey.
The Tutor LMS is affected by the CVE-2026-57694 vulnerability.
Tutor LMS versions up to and including 3.9.13 are vulnerable to CVE-2026-57694.