VYPR

Tutor Lms

by WordPress

Source repositories

CVEs (91)

  • CVE-2020-8615MedFeb 4, 2020
    risk 0.46cvss 6.5epss 0.09

    A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).

  • CVE-2026-19093MedAug 22, 2026
    risk 0.44cvss 6.8epss 0.00

    The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The readable files include the WordPress…

  • CVE-2026-89333MedSep 19, 2026
    risk 0.42cvss 6.5epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2026-40743MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.

  • CVE-2026-3360HigApr 10, 2026
    risk 0.42cvss 7.5epss 0.01

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authentication and authorization checks in the `pay_incomplete_order()` function.…

  • CVE-2025-32223MedMar 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.

  • CVE-2026-23799MedMar 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.5.

  • CVE-2025-13673HigFeb 28, 2026
    risk 0.42cvss 7.5epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2024-43231MedAug 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.3.

  • CVE-2021-24186MedApr 5, 2021
    risk 0.42cvss 6.5epss 0.01

    The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

  • CVE-2021-24185MedApr 5, 2021
    risk 0.42cvss 6.5epss 0.01

    The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

  • CVE-2021-24183MedApr 5, 2021
    risk 0.42cvss 6.5epss 0.02

    The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

  • CVE-2021-24182MedApr 5, 2021
    risk 0.42cvss 6.5epss 0.02

    The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

  • CVE-2021-24181MedApr 5, 2021
    risk 0.42cvss 6.5epss 0.01

    The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

  • CVE-2026-89081MedSep 19, 2026
    risk 0.40cvss 6.1epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2023-0236MedFeb 6, 2023
    risk 0.40cvss 6.1epss 0.01

    The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2021-24873MedNov 23, 2021
    risk 0.40cvss 6.1epss 0.01

    The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue

  • CVE-2024-37947MedJul 20, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.2.

  • CVE-2023-49829MedDec 15, 2023
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.

  • CVE-2026-16759MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.01

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. This is due to missing…

Page 2 of 5