← WordPress Vulnerabilities
WordPress security by component

Tutor LMS

Tutor LMS creates and manages online courses, lessons, quizzes, instructors, enrollments, and student learning content within WordPress.

Tutor LMS (tutor) is a WordPress plugin with 46 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.8.

Plugin slug: tutor

CVE-2026-78175: Tutor LMS withdrawal metadata permits subscriber object injection

Tutor LMS through 4.0.7 passes attacker-controlled withdraw_method_field data through esc_sql(), serializes it into user metadata with update_user_meta(), and later retrieves malformed length declarations that let unserialize() consume attacker-controlled bytes. The tutor_save_withdraw_account AJAX handler relies on a nonce but lacks a role or capability check, so a subscriber can inject an object and use the plugin's bundled PayPal/Guzzle classes to write executable content. Registration can make the path effectively unauthenticated when monetization is enabled.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for tutor
Safe version
Sep 12, 2026 CVE-2026-78175
Tutor LMS withdrawal metadata permits subscriber object injection
Tutor LMS through 4.0.7 passes attacker-controlled withdraw_method_field data through esc_sql(), serializes it into user metadata with update_user_meta(), and later retrieves malformed length declarations that let unserialize() consume attacker-controlled bytes. The tutor_save_withdraw_account AJAX handler relies on a nonce but lacks a role or capability check, so a subscriber can inject an object and use the plugin's bundled PayPal/Guzzle classes to write executable content. Registration can make the path effectively unauthenticated when monetization is enabled.
See mitigation notes
CVE8.8
NVDPending
Aug 28, 2026 CVE-2026-16759
Tutor LMS course filtering permits unauthenticated PHP function execution
Tutor LMS through 4.0.5 exposes tutor_course_filter_ajax without authorization. Attacker-controlled POST keys reach extract() in tutor_load_template(), overwrite template, method_map and context variables, and invoke an arbitrary zero-argument PHP function; calling WordPress edit_user() can create a persistent Subscriber account from request parameters.
See mitigation notes
CVE6.5
NVDPending
Aug 06, 2026 CVE-2026-14306
Tutor LMS permits cross-course paid-content access bypass
Tutor LMS before 3.9.14 does not correctly verify enrollment when authorizing protected course content. A logged-in Subscriber enrolled in at least one course can request paid lessons, quizzes and assignments from other courses without enrolling or purchasing them. The endpoint, action, course or content identifiers, authorization function and whether non-content actions are reachable are not disclosed.
3.9.14
CVE4.3
NVDPending
Jul 28, 2026 CVE-2026-15444
Tutor LMS coupon creation permits administrator-level SQL injection
Tutor LMS through 4.0.1 accepts coupon_code in the authenticated tutor_coupon_create AJAX action after nonce and current-user-capability checks. ajax_create_coupon() passes the value through CouponModel::insert_applies_to() into QueryHelper::insert_multiple_rows(), which concatenates nonnumeric row values into an INSERT statement instead of parameterizing them. An Administrator can inject SQL and extract database information when creating a coupon that applies to specific items. Tutor LMS 4.0.2 changes the multi-row insert to use $wpdb->prepare().
4.0.2
CVE4.9
NVDPending
Jul 16, 2026 CVE-2026-15022
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.0.0.
See mitigation notes
CVE6.5
NVDPending
Jul 13, 2026 CVE-2026-57694
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.13.
3.9.14
CVE6.5
NVDPending
Jul 01, 2026 CVE-2026-13443
Tutor LMS – eLearning and online course solution: Cross-site scripting
Tutor LMS – eLearning and online course solution is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.9.13.
See mitigation notes
CVE6.4
NVDPending
Jun 18, 2026 CVE-2026-10736
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.9.11.
See mitigation notes
CVE4.9
NVDPending
Jun 15, 2026 CVE-2026-40743
Tutor LMS: Broken access control
Tutor LMS is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 3.9.7.
3.9.8
CVE6.5
NVDPending
May 13, 2026 CVE-2026-6965
Tutor LMS – eLearning and online course solution: Broken access control
Tutor LMS – eLearning and online course solution is affected by broken access control. Exploitation requires an authenticated WordPress account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 3.9.9.
See mitigation notes
CVE5.3
NVDPending
Apr 17, 2026 CVE-2026-6080
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.9.8.
See mitigation notes
CVE6.5
NVDPending
Apr 17, 2026 CVE-2026-5502
Tutor LMS – eLearning and online course solution: Cross-site request forgery
Tutor LMS – eLearning and online course solution is affected by cross-site request forgery. Exploitation requires an authenticated subscriber account. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 3.9.8.
See mitigation notes
CVE5.3
NVDPending
Apr 15, 2026 CVE-2026-40740
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
3.9.8
CVE5.4
NVDPending
Apr 11, 2026 CVE-2026-3371
Tutor LMS – eLearning and online course solution: Broken access control
Tutor LMS – eLearning and online course solution is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 3.9.7.
See mitigation notes
CVE4.3
NVDPending
Apr 11, 2026 CVE-2026-3358
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.9.7.
See mitigation notes
CVE5.4
NVDPending
Apr 10, 2026 CVE-2026-3360
Tutor LMS – eLearning and online course solution: Broken access control
Tutor LMS – eLearning and online course solution is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 3.9.7.
See mitigation notes
CVE7.5
NVDPending
Mar 19, 2026 CVE-2025-32223
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Mar 05, 2026 CVE-2026-23799
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 03, 2026 CVE-2026-1375
Tutor LMS – eLearning and online course solution: Broken access control
Tutor LMS – eLearning and online course solution is affected by broken access control. Exploitation requires an authenticated WordPress account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE8.1
NVDPending
Feb 03, 2026 CVE-2026-1371
Tutor LMS – eLearning and online course solution: Sensitive information exposure
Tutor LMS – eLearning and online course solution is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Jan 22, 2026 CVE-2025-47555
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.8
NVDPending
Oct 25, 2025 CVE-2025-6639
Tutor LMS Pro – eLearning and online course solution: Broken access control
Tutor LMS Pro – eLearning and online course solution is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE5.4
NVDPending
Oct 25, 2025 CVE-2025-11564
Tutor LMS – eLearning and online course solution: A security weakness
Tutor LMS – eLearning and online course solution is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 09, 2025 CVE-2025-58993
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Aug 13, 2025 CVE-2025-6184
Tutor LMS Pro – eLearning and online course solution: SQL injection
Tutor LMS Pro – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Apr 10, 2025 CVE-2025-32230
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVDPending
Nov 01, 2024 CVE-2024-43142
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Sep 10, 2024 CVE-2023-2919
Tutor LMS: Cross-site request forgery
Tutor LMS is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Aug 26, 2024 CVE-2024-39645
Tutor LMS: Cross-site request forgery
Tutor LMS is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Aug 18, 2024 CVE-2024-43282
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Aug 12, 2024 CVE-2024-43231
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 20, 2024 CVE-2024-37947
Tutor LMS: Cross-site scripting
Tutor LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Jul 09, 2024 CVE-2024-37266
Tutor LMS: Filesystem traversal
Tutor LMS is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD7.2
Jul 09, 2024 CVE-2024-37256
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Jun 11, 2024 CVE-2023-25799
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.3
NVD8.8
Jun 07, 2024 CVE-2024-5438
Tutor LMS – eLearning and online course solution: Broken access control
Tutor LMS – eLearning and online course solution is affected by broken access control. Exploitation requires an authenticated WordPress account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE4.3
NVD4.3
Jun 07, 2024 CVE-2024-4902
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
May 16, 2024 CVE-2024-4318
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD6.5
May 16, 2024 CVE-2024-4279
Tutor LMS – eLearning and online course solution: Broken access control
Tutor LMS – eLearning and online course solution is affected by broken access control. Exploitation requires an authenticated WordPress account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE6.5
NVD6.5
Mar 21, 2024 CVE-2024-1503
Tutor LMS – eLearning and online course solution: Cross-site request forgery
Tutor LMS – eLearning and online course solution is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 13, 2024 CVE-2024-1751
Tutor LMS – eLearning and online course solution: SQL injection
Tutor LMS – eLearning and online course solution is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Dec 15, 2023 CVE-2023-49829
Tutor LMS – eLearning and online course solution: Cross-site scripting
Tutor LMS – eLearning and online course solution is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Nov 03, 2023 CVE-2023-25990
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.1
NVD8.8
Nov 03, 2023 CVE-2023-25800
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.1
NVD8.8
Nov 03, 2023 CVE-2023-25700
Tutor LMS: SQL injection
Tutor LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.2
NVD9.8
Jul 04, 2023 CVE-2023-3133
Tutor LMS: A security weakness
Tutor LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5