Tutor Lms

WordPress plugin · tutor-lms · WordPress.org ↗
1
Critical
2
High
12
Known total
0
Unfixed
Running Tutor Lms on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
CRITICAL
CVSS 9.8
Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing
CVE.org
>=2.1.3, <4.0.6 v4.0.6 CVE-2026-19092 Aug 27, 2026
HIGH
CVSS 7.2
Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification
CVE.org
>=2.7.1, <4.0.8 v4.0.8 CVE-2026-85569 Sep 16, 2026
HIGH
CVSS 7.1
Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration
CVE.org
>=0, <3.9.13 v3.9.13 CVE-2026-12275 Jul 13, 2026
MEDIUM
CVSS 4.3
Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure
CVE.org
>=4.0.0, <4.0.8 v4.0.8 CVE-2026-85572 Sep 16, 2026
MEDIUM
CVSS 5.3
Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters
CVE.org
>=4.0.0, <4.0.6 v4.0.6 CVE-2026-19094 Aug 26, 2026
MEDIUM
CVSS 6.8
Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path
CVE.org
>=0, <4.0.6 v4.0.6 CVE-2026-19093 Aug 22, 2026
MEDIUM
CVSS 4.3
Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass
CVE.org
>=0, <3.9.14 v3.9.14 CVE-2026-14306 Aug 6, 2026
MEDIUM
CVSS 5.4
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
CVE.org
>=0, <4.0.0 v4.0.0 CVE-2026-14310 Jul 30, 2026
MEDIUM
CVSS 4.3
Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
CVE.org
>=0, <3.9.13 v3.9.13 CVE-2026-12273 Jul 13, 2026
MEDIUM
CVSS 6.5
Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
CVE.org
>=0, <3.9.13 v3.9.13 CVE-2026-12274 Jul 13, 2026
MEDIUM
CVSS 5.4
Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
CVE.org
>=0, <3.9.13 v3.9.13 CVE-2026-12271 Jul 13, 2026
LOW
CVSS 2.7
Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure via IDOR
CVE.org
>=0, <4.0.6 v4.0.6 CVE-2026-14187 Aug 22, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.