WordPress security by component
Tutor LMS
Plugin description
Tutor LMS is a WordPress component with 43 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
tutorLatest vulnerability
CVE-2026-15444: Tutor LMS coupon creation permits administrator-level SQL injection
Tutor LMS through 4.0.1 accepts coupon_code in the authenticated tutor_coupon_create AJAX action after nonce and current-user-capability checks. ajax_create_coupon() passes the value through CouponModel::insert_applies_to() into QueryHelper::insert_multiple_rows(), which concatenates nonnumeric row values into an INSERT statement instead of parameterizing them. An Administrator can inject SQL and extract database information when creating a coupon that applies to specific items. Tutor LMS 4.0.2 changes the multi-row insert to use $wpdb->prepare().
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-15444
Tutor LMS coupon creation permits administrator-level SQL injection
Tutor LMS through 4.0.1 accepts coupon_code in the authenticated tutor_coupon_create AJAX action after nonce and current-user-capability checks. ajax_create_coupon() passes the value through CouponModel::insert_applies_to() into QueryHelper::insert_multiple_rows(), which concatenates nonnumeric row values into an INSERT statement instead of parameterizing them. An Administrator can inject SQL and extract database information when creating a coupon that applies to specific items. Tutor LMS 4.0.2 changes the multi-row insert to use $wpdb->prepare().
|
4.0.2 |
CVE4.9
NVDPending
|
| Jul 16, 2026 |
CVE-2026-15022
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.0.0.
|
> 4.0.0 |
CVE6.5
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57694
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.13.
|
3.9.14 |
CVE6.5
NVDPending
|
| Jul 01, 2026 |
CVE-2026-13443
Tutor LMS – eLearning and online course solution: Cross-site scripting
Tutor LMS – eLearning and online course solution is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.9.13.
|
> 3.9.13 |
CVE6.4
NVDPending
|
| Jun 18, 2026 |
CVE-2026-10736
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.9.11.
|
> 3.9.11 |
CVE4.9
NVDPending
|
| Jun 15, 2026 |
CVE-2026-40743
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.9.7.
|
3.9.8 |
CVE6.5
NVDPending
|
| May 13, 2026 |
CVE-2026-6965
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.9.
|
> 3.9.9 |
CVE5.3
NVDPending
|
| Apr 17, 2026 |
CVE-2026-6080
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.9.8.
|
> 3.9.8 |
CVE6.5
NVDPending
|
| Apr 17, 2026 |
CVE-2026-5502
Tutor LMS – eLearning and online course solution: Cross-site request forgery
Tutor LMS – eLearning and online course solution is affected by cross-site request forgery. Exploitation requires at least subscriber-level access. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.9.8.
|
> 3.9.8 |
CVE5.3
NVDPending
|
| Apr 15, 2026 |
CVE-2026-40740
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
|
3.9.8 |
CVE5.4
NVDPending
|
| Apr 11, 2026 |
CVE-2026-3371
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
|
> 3.9.7 |
CVE4.3
NVDPending
|
| Apr 11, 2026 |
CVE-2026-3358
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
|
> 3.9.7 |
CVE5.4
NVDPending
|
| Apr 10, 2026 |
CVE-2026-3360
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
|
> 3.9.7 |
CVE7.5
NVDPending
|
| Mar 19, 2026 |
CVE-2025-32223
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 05, 2026 |
CVE-2026-23799
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 03, 2026 |
CVE-2026-1375
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Feb 03, 2026 |
CVE-2026-1371
Tutor LMS – eLearning and online course solution: Sensitive information exposure
Tutor LMS – eLearning and online course solution is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 22, 2026 |
CVE-2025-47555
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE3.8
NVDPending
|
| Oct 25, 2025 |
CVE-2025-6639
Tutor LMS Pro – eLearning and online course solution: A security weakness
Tutor LMS Pro – eLearning and online course solution is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Oct 25, 2025 |
CVE-2025-11564
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 09, 2025 |
CVE-2025-58993
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Aug 13, 2025 |
CVE-2025-6184
Tutor LMS Pro – eLearning and online course solution: SQL injection
Tutor LMS Pro – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 10, 2025 |
CVE-2025-32230
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 01, 2024 |
CVE-2024-43142
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Sep 10, 2024 |
CVE-2023-2919
Tutor LMS: Cross-site request forgery
Tutor LMS is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 26, 2024 |
CVE-2024-39645
Tutor LMS: Cross-site request forgery
Tutor LMS is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Aug 18, 2024 |
CVE-2024-43282
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Aug 12, 2024 |
CVE-2024-43231
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 20, 2024 |
CVE-2024-37947
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Jul 09, 2024 |
CVE-2024-37266
Tutor LMS: Filesystem traversal
Tutor LMS is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.9
NVD7.2
|
| Jul 09, 2024 |
CVE-2024-37256
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Jun 11, 2024 |
CVE-2023-25799
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.3
NVD8.8
|
| Jun 07, 2024 |
CVE-2024-5438
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jun 07, 2024 |
CVE-2024-4902
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| May 16, 2024 |
CVE-2024-4318
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD6.5
|
| May 16, 2024 |
CVE-2024-4279
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Mar 21, 2024 |
CVE-2024-1503
Tutor LMS – eLearning and online course solution: Cross-site request forgery
Tutor LMS – eLearning and online course solution is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 13, 2024 |
CVE-2024-1751
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Dec 15, 2023 |
CVE-2023-49829
Tutor LMS – eLearning and online course solution: Cross-site scripting
Tutor LMS – eLearning and online course solution is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Nov 03, 2023 |
CVE-2023-25990
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.1
NVD8.8
|
| Nov 03, 2023 |
CVE-2023-25800
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.1
NVD8.8
|
| Nov 03, 2023 |
CVE-2023-25700
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.2
NVD9.8
|
| Jul 04, 2023 |
CVE-2023-3133
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|