VYPR

Tutor Lms

by WordPress

Source repositories

CVEs (91)

  • CVE-2024-5438MedJun 7, 2024
    risk 0.21cvss 4.3epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key. This makes it possible…

  • CVE-2026-14187LowAug 22, 2026
    risk 0.18cvss 2.7epss 0.00

    The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

  • CVE-2026-14310MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to…

  • CVE-2026-15444MedJul 28, 2026
    risk 0.00cvss 4.9epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15022MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.01

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-57694MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

  • CVE-2026-12275HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to…

  • CVE-2026-12274MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users…

  • CVE-2026-12273MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post…

  • CVE-2026-12271MedJul 13, 2026
    risk 0.00cvss 5.4epss 0.00

    The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded…

  • CVE-2026-13443MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible…

Page 5 of 5