CVE-2026-3371 | themeum Tutor LMS Plugin up to 3.9.7 on WordPress AJAX save_course_content_order authorization (EUVD-2026-21615)
A vulnerability categorized as critical has been discovered in themeum Tutor LMS Plugin up to 3.9.7 on WordPress. This affects the function save_course_content_order of the component AJAX Handler. The manipulation results in authorization bypass.
This vulnerability is reported as CVE-2026-3371. The attack can be launched remotely. No exploit exists.