← WordPress Vulnerabilities
WordPress security by component

Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Feb 28, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: tutor-lms-elearning-and-online-course-solution

CVE-2025-13673: Tutor LMS – eLearning and online course solution: SQL injection

Tutor LMS – eLearning and online course solution is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.

PublishedFeb 28, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 28, 2026 CVE-2025-13673
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Jan 20, 2026 CVE-2026-0548
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jan 09, 2026 CVE-2025-13935
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 09, 2026 CVE-2025-13934
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 09, 2026 CVE-2025-13628
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 08, 2026 CVE-2025-13679
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending