Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. This is due to missing authorization on the handler combined with unsani...
- CVSS:
- 6.5
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.6
- Disclosed:
- Aug 27, 2026
CVE-2026-16759 on NVD →
Tutor LMS – eLearning and online course solution < 4.0.0 - Missing Authorization
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 30, 2026
CVE-2026-14310 on NVD →
Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make...
- CVSS:
- 4.9
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Jul 27, 2026
CVE-2026-15444 on NVD →
Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...
- CVSS:
- 6.5
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.1
- Disclosed:
- Jul 15, 2026
CVE-2026-15022 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.13 - Unauthenticated Insecure Direct Object Reference
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.13 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perf...
- CVSS:
- 4.3
- Affected:
- up to 3.9.13
- Fixed in:
- 3.9.14
- Disclosed:
- Jul 6, 2026
CVE-2026-57694 on NVD →
Tutor LMS <= 3.9.13 - Authenticated (Subscriber+) Information Exposure
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to vie paid course content.
- CVSS:
- 4.3
- Affected:
- up to 3.9.13
- Fixed in:
- 3.9.14
- Disclosed:
- Jul 2, 2026
CVE-2026-14306 on NVD →
Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-leve...
- CVSS:
- 6.4
- Affected:
- up to 3.9.13
- Fixed in:
- 3.9.14
- Disclosed:
- Jun 30, 2026
CVE-2026-13443 on NVD →
Tutor LMS <= 3.9.12 - Authenticated (Subscriber+) Information Disclosure
medium
The Tutor LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enroll in unauthorized courses and private content.
- CVSS:
- 4.3
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.13
- Disclosed:
- Jun 22, 2026
CVE-2026-12275 on NVD →
Tutor LMS <= 3.9.12 - Missing Authorization to Authenticated (Subscriber+) Comment Creation
medium
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create comments without approval.
- CVSS:
- 4.3
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.13
- Disclosed:
- Jun 22, 2026
CVE-2026-12273 on NVD →
Tutor LMS <= 3.9.12 - Authenticated (Subscriber+) Insecure Direct Object Reference to Quiz Attemp Modification
medium
The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.12 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify quiz attempts.
- CVSS:
- 4.3
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.13
- Disclosed:
- Jun 22, 2026
CVE-2026-12271 on NVD →
Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...
- CVSS:
- 4.9
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.12
- Disclosed:
- Jun 17, 2026
CVE-2026-10736 on NVD →
Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.9.9. This is due to the `get_course_id_by()` function unconditionally trusting the user-supplied `course` GET parameter as the authoritative course ID for content...
- CVSS:
- 5.3
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.10
- Disclosed:
- May 12, 2026
CVE-2026-6965 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.7 - Missing Authorization
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Apr 20, 2026
CVE-2026-40743 on NVD →
Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter
medium
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter combined with direct interpolation into a SQL fragment before being passed to $wpdb->prepare(). This makes it possible for authenticated attackers with Ad...
- CVSS:
- 6.5
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.9
- Disclosed:
- Apr 16, 2026
CVE-2026-6080 on NVD →
Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_course_content_order() function. The function only validates the nonce (CSRF protect...
- CVSS:
- 5.3
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.9
- Disclosed:
- Apr 16, 2026
CVE-2026-5502 on NVD →
Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authorization checks in the `save_course_content_order()` private method, which is called unconditionally by the `tutor_update_c...
- CVSS:
- 4.3
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Apr 10, 2026
CVE-2026-3371 on NVD →
Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, 3.9.7. This is due to missing post_status validation in the `enroll_now()` and `course_enrollment()` functions. Both enrollment endpoints verify the non...
- CVSS:
- 5.4
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Apr 10, 2026
CVE-2026-3358 on NVD →
Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter
high
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authentication and authorization checks in the `pay_incomplete_order()` function. The function accepts an attacker-controlled...
- CVSS:
- 7.5
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Apr 9, 2026
CVE-2026-3360 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.4 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perfo...
- CVSS:
- 4.3
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- Mar 16, 2026
CVE-2025-32223 on NVD →
Tutor LMS <= 3.9.7 - Missing Authorization
medium
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Mar 15, 2026
CVE-2026-40740 on NVD →
Tutor LMS - Unauthenticated SQL Injection via coupon_code vulnerability
critical
Unauthenticated SQL Injection via coupon_code vulnerability
- CVSS:
- 9.3
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.7
- Disclosed:
- Mar 2, 2026
Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code
high
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po...
- CVSS:
- 7.5
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.7
- Disclosed:
- Feb 27, 2026
CVE-2025-13673 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.5 - Missing Authorization
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthoriz...
- CVSS:
- 4.3
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Feb 25, 2026
CVE-2026-23799 on NVD →
Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.5. This is due to missing authorization checks in the `ajax_coupon_details()` function, which only validates nonces but does not verify user capabilities. T...
- CVSS:
- 5.3
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Feb 2, 2026
CVE-2026-1371 on NVD →
Tutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion
high
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3.9.5. This is due to missing object-level authorization checks in the `course_list_bulk_action()`, `bulk_delete_course()`, and `update_course_status(...
- CVSS:
- 8.1
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Feb 2, 2026
CVE-2026-1375 on NVD →
Tutor LMS – eLearning and online course solution [tutor] <= 3.9.4 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.
- Affected:
- up to 3.9.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-47555 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment deletion due to a missing capability check on the `delete_existing_user_photo` function in all versions up to, and including, 3.9.4. This makes it possible for authenticated attackers, with subscriber leve...
- CVSS:
- 5.4
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- Jan 20, 2026
CVE-2026-0548 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 3.9.4
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated attackers, with subs...
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 9, 2026
CVE-2025-13935 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 3.9.4
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authen...
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 9, 2026
CVE-2025-13934 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 3.9.4
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for au...
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 9, 2026
CVE-2025-13628 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for authent...
- CVSS:
- 4.3
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 8, 2026
CVE-2025-13628 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated attackers, with subscribe...
- CVSS:
- 4.3
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 8, 2026
CVE-2025-13935 on NVD →
Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authenticat...
- CVSS:
- 4.3
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 8, 2026
CVE-2025-13934 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 3.9.4
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access an...
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 8, 2026
CVE-2025-13679 on NVD →
Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and abo...
- CVSS:
- 6.5
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.4
- Disclosed:
- Jan 7, 2026
CVE-2025-13679 on NVD →
Tutor LMS <= 3.9.4 - Authenticated (Instructor+) Insecure Direct Object Reference
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to perform a...
- CVSS:
- 4.3
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- Jan 2, 2026
CVE-2025-47555 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 3.9.0
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check while verifying webhook signatures on the "verifyAndCreateOrderData" function
in all versions up to, and including, 3.8.3. This makes it possible for una...
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0
- Disclosed:
- Oct 25, 2025
CVE-2025-11564 on NVD →
Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3. This makes it possible for authenticated attackers, with tutor-level access and above, to view assignments for courses they don't teach which may contain...
- CVSS:
- 4.3
- Affected:
- up to 3.8.3
- Fixed in:
- 3.9.0
- Disclosed:
- Oct 24, 2025
CVE-2025-6680 on NVD →
Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check while verifying webhook signatures on the "verifyAndCreateOrderData" function
in all versions up to, and including, 3.8.3. This makes it possible for unauthen...
- CVSS:
- 5.3
- Affected:
- up to 3.8.3
- Fixed in:
- 3.9.0
- Disclosed:
- Oct 24, 2025
CVE-2025-11564 on NVD →
Tutor LMS <= 3.7.4 - Authenticated (Administrator+) SQL Injection
medium
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abo...
- CVSS:
- 4.9
- Affected:
- up to 3.7.4
- Fixed in:
- 3.8.0
- Disclosed:
- Sep 9, 2025
CVE-2025-58993 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 3.8.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4.
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Sep 9, 2025
CVE-2025-58993 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 3.4.1
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Apr 10, 2025
CVE-2025-32230 on NVD →
Tutor LMS <= 3.4.0 - Authenticated (Subscriber+) HTML Injection
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 3.4.0. This is due to the plugin not properly restricting HTML content from subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.1
- Disclosed:
- Apr 7, 2025
CVE-2025-32230 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.7
unknown
[en] The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on...
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
- Disclosed:
- Nov 21, 2024
CVE-2024-10393 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.7
unknown
[en] The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
- Disclosed:
- Nov 21, 2024
CVE-2024-10400 on NVD →
Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter
high
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...
- CVSS:
- 7.5
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.7
- Disclosed:
- Nov 20, 2024
CVE-2024-10400 on NVD →
Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration
medium
The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the s...
- CVSS:
- 5.3
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.7
- Disclosed:
- Nov 20, 2024
CVE-2024-10393 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.4
unknown
[en] Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7.3.
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Nov 1, 2024
CVE-2024-43142 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.5
unknown
[en] The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for unauthenticated attackers to enable or disable addons via a forged request...
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Sep 10, 2024
CVE-2023-2919 on NVD →
Tutor LMS <= 2.7.4 - Cross-Site Request Forgery via 'addon_enable_disable'
medium
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for unauthenticated attackers to enable or disable addons via a forged request grant...
- CVSS:
- 4.3
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.5
- Disclosed:
- Sep 9, 2024
CVE-2023-2919 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Aug 26, 2024
CVE-2024-39645 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.3
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Aug 18, 2024
CVE-2024-43282 on NVD →
Tutor LMS <= 2.7.2 - Authenticated (Administrator+) SQL Injection
high
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abo...
- CVSS:
- 7.2
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- Aug 16, 2024
CVE-2024-43282 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.3.
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Aug 12, 2024
CVE-2024-43231 on NVD →
Tutor LMS <= 2.7.3 - Authenticated (Instructor+) Stored Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with instructor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 5.5
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- Aug 9, 2024
CVE-2024-43231 on NVD →
Tutor LMS <= 2.7.3 - Missing Authorization
medium
The Tutor LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_or_update_annoucement, tutor_quiz_save, tutor_load_edit_lesson_modal, and tutor_modal_create_or_update_lesson functions in versions up to, and including, 2.7.3. This makes it possible f...
- CVSS:
- 5.3
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- Aug 7, 2024
CVE-2024-43142 on NVD →
Tutor LMS <= 2.7.2 - Cross-Site Request Forgery
medium
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.2. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete course via a forged request granted they can trick a site admi...
- CVSS:
- 4.3
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- Aug 1, 2024
CVE-2024-39645 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.3
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.2.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Jul 20, 2024
CVE-2024-37947 on NVD →
Tutor LMS <= 2.7.2 - Authenticated (Tutor Instructor+) Stored Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with tutor instructor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 5.5
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- Jul 10, 2024
CVE-2024-37947 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.2
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a through 2.7.1.
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Jul 9, 2024
CVE-2024-37266 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.1.
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Jul 9, 2024
CVE-2024-37256 on NVD →
Tutor LMS <= 2.7.1 - Authenticated (Admin+) Path Traversal
low
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 2.7
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.2
- Disclosed:
- Jun 27, 2024
CVE-2024-37266 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.1.9
unknown
[en] Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
- Disclosed:
- Jun 11, 2024
CVE-2023-25799 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.2
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Jun 7, 2024
CVE-2024-4902 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.2
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Inst...
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Jun 7, 2024
CVE-2024-5438 on NVD →
Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection
high
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma...
- CVSS:
- 7.2
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.2
- Disclosed:
- Jun 6, 2024
CVE-2024-4902 on NVD →
Tutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Instructo...
- CVSS:
- 4.3
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.2
- Disclosed:
- Jun 6, 2024
CVE-2024-5438 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.1
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow authenticated at...
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.1
- Disclosed:
- May 16, 2024
CVE-2024-4279 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.1
unknown
[en] The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.1
- Disclosed:
- May 16, 2024
CVE-2024-4318 on NVD →
Tutor LMS <= 2.7.0 - Missing Authorization
critical
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.
- CVSS:
- 9.8
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.1
- Disclosed:
- May 15, 2024
CVE-2024-4223 on NVD →
Tutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL Injection
high
The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...
- CVSS:
- 8.8
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.1
- Disclosed:
- May 15, 2024
CVE-2024-4318 on NVD →
Tutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course Deletion
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow authenticated attacke...
- CVSS:
- 6.5
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.1
- Disclosed:
- May 15, 2024
CVE-2024-4279 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.0
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices function in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to enable user registration o...
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- May 2, 2024
CVE-2024-3553 on NVD →
Tutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options Update
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices function in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to enable user registration on sit...
- CVSS:
- 6.5
- Affected:
- up to 2.6.2
- Fixed in:
- 2.7.0
- Disclosed:
- Apr 26, 2024
CVE-2024-3553 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.7.0
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tutor_instructor_list' shortcode in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Apr 25, 2024
CVE-2024-3994 on NVD →
Tutor LMS – eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' Shortcode
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tutor_instructor_list' shortcode in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...
- CVSS:
- 5.4
- Affected:
- up to 2.6.2
- Fixed in:
- 2.7.0
- Disclosed:
- Apr 24, 2024
CVE-2024-3994 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.6.2
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.2
- Disclosed:
- Mar 13, 2024
CVE-2024-1751 on NVD →
Tutor LMS – eLearning and online course solution <= 2.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. This makes it possible for authenticated attackers, with subscriber-level access...
- CVSS:
- 5.4
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Mar 12, 2024
CVE-2024-1502 on NVD →
Tutor LMS – eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the erase_tutor_data() function. This makes it possible for unauthenticated attackers to deactivate t...
- CVSS:
- 4.3
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Mar 12, 2024
CVE-2024-1503 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.6.2
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the erase_tutor_data() function. This makes it possible for unauthenticated attackers to deactiv...
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.2
- Disclosed:
- Mar 12, 2024
CVE-2024-1503 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.6.2
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. This makes it possible for authenticated attackers, with subscriber-level a...
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.2
- Disclosed:
- Mar 12, 2024
CVE-2024-1502 on NVD →
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
high
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma...
- CVSS:
- 8.8
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Mar 11, 2024
CVE-2024-1751 on NVD →
Tutor LMS <= 2.6.0 - Authenticated(Student+) HTML Injection via Q&A
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.6.0. This is due to insufficient sanitization of HTML input in the Q&A functionality. This makes it possible for authenticated attackers, with Student access and above, to in...
- CVSS:
- 5.4
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Feb 20, 2024
CVE-2024-1128 on NVD →
Tutor LMS <= 2.6.0 - Missing Authorization
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restricted Q&A content due to a missing capability check when interacting with questions in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with subscriber acce...
- CVSS:
- 4.3
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Feb 20, 2024
CVE-2024-1133 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.6.1
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restricted Q&A content due to a missing capability check when interacting with questions in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with subscriber...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Feb 20, 2024
CVE-2024-1133 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.6.1
unknown
[en] The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.6.0. This is due to insufficient sanitization of HTML input in the Q&A functionality. This makes it possible for authenticated attackers, with Student access and above,...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Feb 20, 2024
CVE-2024-1128 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.3.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Dec 15, 2023
CVE-2023-49829 on NVD →
Tutor LMS <= 2.2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level p...
- CVSS:
- 4.4
- Affected:
- up to 2.2.4
- Fixed in:
- 2.3.0
- Disclosed:
- Dec 5, 2023
CVE-2023-49829 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.2.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Nov 3, 2023
CVE-2023-25990 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.2.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Nov 3, 2023
CVE-2023-25700 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.2.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0.
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Nov 3, 2023
CVE-2023-25800 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.3.0
unknown
[en] The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Oct 16, 2023
CVE-2023-4805 on NVD →
Tutor LMS <= 2.2.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber access to inject arbitrary web scripts in pages that will execute wheneve...
- CVSS:
- 6.4
- Affected:
- up to 2.2.4
- Fixed in:
- 2.3.0
- Disclosed:
- Sep 25, 2023
CVE-2023-4805 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.2.1
unknown
[en] The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Jul 4, 2023
CVE-2023-3133 on NVD →
Tutor LMS <= 2.2.0 - Missing Authorization via REST API
high
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on various REST API endpoints in versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to view quiz questions and answers as well as student quiz attempts and author info...
- CVSS:
- 7.5
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 12, 2023
CVE-2023-3133 on NVD →
Tutor LMS <= 2.1.10 - Unauthenticated SQL Injection
critical
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, 2.1.10 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additi...
- CVSS:
- 9.8
- Affected:
- up to 2.1.10
- Fixed in:
- 2.2.0
- Disclosed:
- May 30, 2023
CVE-2023-25700 on NVD →
Tutor LMS <= 2.2.0 - Authenticated (Student+) SQL Injection
high
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with student-level...
- CVSS:
- 8.8
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- May 30, 2023
CVE-2023-25800 on NVD →
Tutor LMS <= 2.1.10 - Authenticated (Tutor Instructor+) SQL Injection
high
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, 2.1.10 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with tutor instru...
- CVSS:
- 8.8
- Affected:
- up to 2.1.10
- Fixed in:
- 2.2.0
- Disclosed:
- May 30, 2023
CVE-2023-25990 on NVD →
Tutor LMS <= 2.1.8 - Missing Authorization via multiple AJAX actions
medium
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access, modification, or loss of data due to a missing capability check on the multiple functions in versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with student-level access and above, to perform actions such as...
- CVSS:
- 5.4
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- May 24, 2023
CVE-2023-25799 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 2.0.10
unknown
[en] The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.10
- Disclosed:
- Feb 6, 2023
CVE-2023-0236 on NVD →
Tutor LMS <= 2.0.9 - Reflected Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reset_key' and 'user_id' parameters (used by the password retrieval form) in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...
- CVSS:
- 6.1
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.10
- Disclosed:
- Jan 12, 2023
CVE-2023-0236 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.9.13
unknown
Update the WordPress Tutor LMS plugin to the latest available version (at least 1.9.13).
WPScanTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Tutor LMS Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML paylo...
- Affected:
- up to 1.9.13
- Fixed in:
- 1.9.13
- Disclosed:
- Jan 10, 2023
Tutor LMS – eLearning and online course solution [tutor] < 2.0.10
unknown
[en] The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.10
- Disclosed:
- Oct 17, 2022
CVE-2022-2563 on NVD →
Tutor LMS <= 2.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the topic name and lesson name parameters in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...
- CVSS:
- 5.5
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.10
- Disclosed:
- Sep 26, 2022
CVE-2022-2563 on NVD →
Tutor LMS – eLearning and online course solution 2.0.0-2.0.8 - Reflected Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions 2.0.0-2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into per...
- CVSS:
- 6.1
- Affected:
- 2.0.0 – 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Aug 22, 2022
Tutor LMS – eLearning and online course solution [tutor] < 2.0.9
unknown
The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions 2.0.0-2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into per...
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Aug 22, 2022
Tutor LMS – eLearning and online course solution [tutor] < 1.9.12
unknown
[en] The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.12
- Disclosed:
- Jan 24, 2022
CVE-2021-25017 on NVD →
Tutor LMS <= 1.9.11 - Stored Cross-Site Scripting
high
The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user profile parameters in versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inj...
- CVSS:
- 7.2
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.12
- Disclosed:
- Dec 27, 2021
Tutor LMS <= 1.9.11 - Reflected Cross-Site Scripting
medium
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.12
- Disclosed:
- Dec 27, 2021
CVE-2021-25017 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.9.12
unknown
Stored Cross-Site Scripting (XSS) vulnerability discovered by creadpag in WordPress Tutor LMS plugin (versions <= 1.9.11).
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.12
- Disclosed:
- Dec 27, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.9.12
unknown
The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user profile parameters in versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inj...
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.12
- Disclosed:
- Dec 27, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.9.11
unknown
[en] The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.11
- Disclosed:
- Nov 23, 2021
CVE-2021-24873 on NVD →
Tutor LMS <= 1.9.10 - Reflected Cross-Site Scripting
medium
The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 1.9.10
- Fixed in:
- 1.9.11
- Disclosed:
- Oct 19, 2021
CVE-2021-24873 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.9.9
unknown
[en] The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9
- Disclosed:
- Oct 18, 2021
CVE-2021-24740 on NVD →
Tutor LMS <= 1.9.8 - Admin+ Stored Cross-Site Scripting
medium
The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9
- Disclosed:
- Sep 20, 2021
CVE-2021-24740 on NVD →
Tutor LMS <= 1.9.5 - Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- CVSS:
- 6.1
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.6
- Disclosed:
- Aug 9, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.9.6
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Tutor LMS plugin (versions <= 1.9.5).
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
- Disclosed:
- Aug 9, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.9.6
unknown
The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
- Disclosed:
- Aug 9, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.9.2
unknown
[en] The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Instructor. This lead to a Stored Cross-Site Scripting issue, which is triggered when viewing the...
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Aug 2, 2021
CVE-2021-24455 on NVD →
Tutor LMS <= 1.9.1 - Authenticated Stored Cross-Site Scripting
medium
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Instructor. This lead to a Stored Cross-Site Scripting issue, which is triggered when viewing the Annou...
- CVSS:
- 5.5
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Jun 28, 2021
CVE-2021-24455 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.8.8
unknown
[en] The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include any local php file
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Apr 22, 2021
CVE-2021-24242 on NVD →
Tutor LMS <= 1.8.7 - Authenticated Local File Inclusion
medium
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include any local php file
- CVSS:
- 5.5
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.8
- Disclosed:
- Apr 5, 2021
CVE-2021-24242 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.7.7
unknown
[en] The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Apr 5, 2021
CVE-2021-24181 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.8.3
unknown
[en] The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Apr 5, 2021
CVE-2021-24183 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.7.7
unknown
[en] Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Apr 5, 2021
CVE-2021-24184 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.7.7
unknown
[en] The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Apr 5, 2021
CVE-2021-24185 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.8.3
unknown
[en] The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Apr 5, 2021
CVE-2021-24182 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.8.3
unknown
[en] The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Apr 5, 2021
CVE-2021-24186 on NVD →
Tutor LMS – eLearning and online course solution <= 1.7.6 - Unprotected AJAX including Privilege Escalation
high
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.
- CVSS:
- 8.8
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2021
CVE-2021-24184 on NVD →
Tutor LMS <=1.8.2 - SQL Injection via tutor_quiz_builder_get_answers_by_question
high
The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
- CVSS:
- 8.8
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Mar 15, 2021
CVE-2021-24182 on NVD →
Tutor LMS <=1.8.2 - SQL Injection via tutor_answering_quiz_question/get_answer_by_id
high
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
- CVSS:
- 8.8
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Mar 15, 2021
CVE-2021-24186 on NVD →
Tutor LMS <= 1.8.2 - SQL Injection via tutor_quiz_builder_get_question_form
medium
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
- CVSS:
- 6.5
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Mar 15, 2021
CVE-2021-24183 on NVD →
Tutor LMS – eLearning and online course solution <=1.7.6 - SQL Injection
medium
The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
- CVSS:
- 6.5
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2021
CVE-2021-24185 on NVD →
Tutor LMS – eLearning and online course solution <= 1.7.6 - SQL Injection
medium
The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
- CVSS:
- 6.5
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2021
CVE-2021-24181 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.7.7
unknown
Multiple Blind/Time-based SQL Injection (SQLi) vulnerabilities were discovered by WordFence in the WordPress Tutor LMS plugin (versions <= 1.7.6).
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.8.3
unknown
Multiple Union SQL Injection (SQLi) vulnerabilities were discovered by WordFence in the WordPress Tutor LMS plugin (versions <= 1.8.2).
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Mar 15, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.7.7
unknown
Unprotected AJAX Action to Privilege Escalation vulnerability discovered by WordFence in WordPress Tutor LMS plugin (versions <= 1.7.6).
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2021
Tutor LMS <= 1.9.12 - Reflected Cross-Site Scripting
medium
The Tutor LMS plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 1.9.12 due to missing input and output sanitization of some user generated URLs.
- CVSS:
- 6.1
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.13
- Disclosed:
- Jan 10, 2021
Tutor LMS – eLearning and online course solution [tutor] < 1.9.13
unknown
The Tutor LMS plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 1.9.12 due to missing input and output sanitization of some user generated URLs.
- Affected:
- up to 1.9.13
- Fixed in:
- 1.9.13
- Disclosed:
- Jan 10, 2021
Tutor LMS < 1.5.3 - Cross-Site Request Forgery
high
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
- CVSS:
- 8.8
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Feb 4, 2020
CVE-2020-8615 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.5.3
unknown
[en] A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Feb 4, 2020
CVE-2020-8615 on NVD →
Tutor LMS – eLearning and online course solution [tutor] < 1.5.3
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jinson Varghese Behanan in WordPress Tutor LMS plugin (versions <= 1.5.2).
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Feb 4, 2020
Tutor LMS – eLearning and online course solution [tutor] < 1.9.13
unknown
The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 1.9.13
- Fixed in:
- 1.9.13
Tutor LMS – eLearning and online course solution [tutor] < 1.9.12
unknown
The plugin does not escape the 'Job Title" field of user's profile, which could allow any authenticated users to set a Cross-Site Scripting payload in it, which will be triggered when an admin edit the related profile
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.12
Tutor LMS – eLearning and online course solution [tutor] < 1.9.6
unknown
The plugin does not escape a page parameter before outputting it back in an student dashboard page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
Tutor LMS – eLearning and online course solution [tutor] < 1.9.11
unknown
The plugin does not escape an URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting
The issue was initially fixed in 1.9.13 but re-introduced in 2.0.0
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.11