← WordPress Vulnerabilities
WordPress security by component

Tutor LMS

Tutor LMS is a WordPress component with 43 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: tutor

CVE-2026-15444: Tutor LMS coupon creation permits administrator-level SQL injection

Tutor LMS through 4.0.1 accepts coupon_code in the authenticated tutor_coupon_create AJAX action after nonce and current-user-capability checks. ajax_create_coupon() passes the value through CouponModel::insert_applies_to() into QueryHelper::insert_multiple_rows(), which concatenates nonnumeric row values into an INSERT statement instead of parameterizing them. An Administrator can inject SQL and extract database information when creating a coupon that applies to specific items. Tutor LMS 4.0.2 changes the multi-row insert to use $wpdb->prepare().

PublishedJul 28, 2026
Known safe version4.0.2
Safe version
Jul 28, 2026 CVE-2026-15444
Tutor LMS coupon creation permits administrator-level SQL injection
Tutor LMS through 4.0.1 accepts coupon_code in the authenticated tutor_coupon_create AJAX action after nonce and current-user-capability checks. ajax_create_coupon() passes the value through CouponModel::insert_applies_to() into QueryHelper::insert_multiple_rows(), which concatenates nonnumeric row values into an INSERT statement instead of parameterizing them. An Administrator can inject SQL and extract database information when creating a coupon that applies to specific items. Tutor LMS 4.0.2 changes the multi-row insert to use $wpdb->prepare().
4.0.2
CVE4.9
NVDPending
Jul 16, 2026 CVE-2026-15022
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.0.0.
> 4.0.0
CVE6.5
NVDPending
Jul 13, 2026 CVE-2026-57694
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.13.
3.9.14
CVE6.5
NVDPending
Jul 01, 2026 CVE-2026-13443
Tutor LMS – eLearning and online course solution: Cross-site scripting
Tutor LMS – eLearning and online course solution is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.9.13.
> 3.9.13
CVE6.4
NVDPending
Jun 18, 2026 CVE-2026-10736
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.9.11.
> 3.9.11
CVE4.9
NVDPending
Jun 15, 2026 CVE-2026-40743
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.9.7.
3.9.8
CVE6.5
NVDPending
May 13, 2026 CVE-2026-6965
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.9.
> 3.9.9
CVE5.3
NVDPending
Apr 17, 2026 CVE-2026-6080
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.9.8.
> 3.9.8
CVE6.5
NVDPending
Apr 17, 2026 CVE-2026-5502
Tutor LMS – eLearning and online course solution: Cross-site request forgery
Tutor LMS – eLearning and online course solution is affected by cross-site request forgery. Exploitation requires at least subscriber-level access. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.9.8.
> 3.9.8
CVE5.3
NVDPending
Apr 15, 2026 CVE-2026-40740
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
3.9.8
CVE5.4
NVDPending
Apr 11, 2026 CVE-2026-3371
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
> 3.9.7
CVE4.3
NVDPending
Apr 11, 2026 CVE-2026-3358
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
> 3.9.7
CVE5.4
NVDPending
Apr 10, 2026 CVE-2026-3360
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
> 3.9.7
CVE7.5
NVDPending
Mar 19, 2026 CVE-2025-32223
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Mar 05, 2026 CVE-2026-23799
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 03, 2026 CVE-2026-1375
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVDPending
Feb 03, 2026 CVE-2026-1371
Tutor LMS – eLearning and online course solution: Sensitive information exposure
Tutor LMS – eLearning and online course solution is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Jan 22, 2026 CVE-2025-47555
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.8
NVDPending
Oct 25, 2025 CVE-2025-6639
Tutor LMS Pro – eLearning and online course solution: A security weakness
Tutor LMS Pro – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Oct 25, 2025 CVE-2025-11564
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 09, 2025 CVE-2025-58993
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Aug 13, 2025 CVE-2025-6184
Tutor LMS Pro – eLearning and online course solution: SQL injection
Tutor LMS Pro – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Apr 10, 2025 CVE-2025-32230
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVDPending
Nov 01, 2024 CVE-2024-43142
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Sep 10, 2024 CVE-2023-2919
Tutor LMS: Cross-site request forgery
Tutor LMS is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Aug 26, 2024 CVE-2024-39645
Tutor LMS: Cross-site request forgery
Tutor LMS is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Aug 18, 2024 CVE-2024-43282
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Aug 12, 2024 CVE-2024-43231
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 20, 2024 CVE-2024-37947
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Jul 09, 2024 CVE-2024-37266
Tutor LMS: Filesystem traversal
Tutor LMS is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD7.2
Jul 09, 2024 CVE-2024-37256
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Jun 11, 2024 CVE-2023-25799
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.3
NVD8.8
Jun 07, 2024 CVE-2024-5438
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Jun 07, 2024 CVE-2024-4902
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
May 16, 2024 CVE-2024-4318
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD6.5
May 16, 2024 CVE-2024-4279
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Mar 21, 2024 CVE-2024-1503
Tutor LMS – eLearning and online course solution: Cross-site request forgery
Tutor LMS – eLearning and online course solution is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 13, 2024 CVE-2024-1751
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Dec 15, 2023 CVE-2023-49829
Tutor LMS – eLearning and online course solution: Cross-site scripting
Tutor LMS – eLearning and online course solution is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Nov 03, 2023 CVE-2023-25990
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.1
NVD8.8
Nov 03, 2023 CVE-2023-25800
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.1
NVD8.8
Nov 03, 2023 CVE-2023-25700
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.2
NVD9.8
Jul 04, 2023 CVE-2023-3133
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5