📦 Tutor Lms

by Themeum

🔍 What is Tutor Lms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-4223

CRITICAL CVSS 9.8 May 16, 2024

The Tutor LMS WordPress plugin has a missing capability check vulnerability that allows unauthenticated attackers to add, modify, or delete data. This affects all versions up to and including 2.7.0. A...

CVE-2024-10400

HIGH CVSS 7.5 Nov 21, 2024

This SQL injection vulnerability in the Tutor LMS WordPress plugin allows unauthenticated attackers to inject malicious SQL queries through the 'rating_filter' parameter. Attackers can extract sensiti...

CVE-2024-5784

HIGH CVSS 7.1 Aug 30, 2024

The Tutor LMS Pro WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or higher to perform administrative actions. This includes ...

CVE-2024-37256

HIGH CVSS 7.6 Jul 9, 2024

This SQL injection vulnerability in Tutor LMS WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all Tutor LMS installations up to version 2.7.1. Attackers...

CVE-2023-25799

HIGH CVSS 8.3 Jun 11, 2024

CVE-2023-25799 is a missing authorization vulnerability in the Tutor LMS WordPress plugin that allows unauthorized users to access student data and perform actions they shouldn't be able to. This affe...

CVE-2024-4902

HIGH CVSS 7.2 Jun 7, 2024

This vulnerability allows authenticated attackers with admin-level access in Tutor LMS WordPress plugin to perform time-based SQL injection attacks via the 'course_id' parameter. Attackers can extract...

CVE-2024-4352

HIGH CVSS 8.8 May 16, 2024

This vulnerability in Tutor LMS Pro WordPress plugin allows authenticated attackers with subscriber-level permissions or higher to bypass authorization checks and execute SQL injection attacks. Attack...

CVE-2024-4222

HIGH CVSS 7.3 May 16, 2024

The Tutor LMS Pro WordPress plugin up to version 2.7.0 lacks proper capability checks on multiple functions, allowing unauthenticated attackers to add, modify, or delete user metadata and plugin setti...

CVE-2024-4318

HIGH CVSS 8.8 May 16, 2024

This vulnerability allows authenticated attackers with Instructor-level permissions or higher in Tutor LMS for WordPress to perform time-based SQL injection attacks via the 'question_id' parameter. At...

CVE-2024-1751

HIGH CVSS 8.8 Mar 13, 2024

This vulnerability allows authenticated attackers with subscriber/student access or higher to perform time-based SQL injection attacks via the question_id parameter in Tutor LMS WordPress plugin. Atta...

CVE-2023-25800

HIGH CVSS 8.8 Nov 3, 2023

This SQL injection vulnerability in the Tutor LMS WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all Tutor LMS installations up to version 2.2.0, poten...

CVE-2023-3133

HIGH CVSS 7.5 Jul 4, 2023

This vulnerability allows unauthenticated attackers to access private lesson information in Tutor LMS WordPress plugin. WordPress sites using Tutor LMS versions before 2.2.1 are affected. The issue st...

CVE-2021-24184

HIGH CVSS 8.8 Apr 5, 2021

This vulnerability in Tutor LMS WordPress plugin allows students to access unprotected AJAX endpoints, enabling them to modify course information and escalate privileges. It affects WordPress sites us...

CVE-2025-6680

MEDIUM CVSS 4.3 Oct 25, 2025

The Tutor LMS WordPress plugin up to version 3.8.3 contains an access control vulnerability that allows authenticated users with tutor-level permissions or higher to view assignments from courses they...

CVE-2025-11564

MEDIUM CVSS 5.3 Oct 25, 2025

This vulnerability in Tutor LMS WordPress plugin allows unauthenticated attackers to bypass payment verification by forging webhook requests with 'recurring' payment_type. Attackers can mark orders as...

CVE-2024-10393

MEDIUM CVSS 5.3 Nov 21, 2024

The Tutor LMS WordPress plugin vulnerability allows unauthenticated attackers to register user accounts even when site registration is disabled. This affects WordPress sites using Tutor LMS version 2....

CVE-2024-43231

MEDIUM CVSS 6.5 Aug 12, 2024

A stored cross-site scripting (XSS) vulnerability in the Tutor LMS WordPress plugin allows attackers to inject malicious scripts into web pages. When users view affected pages, the scripts execute in ...

CVE-2024-37947

MEDIUM CVSS 5.9 Jul 20, 2024

This stored cross-site scripting (XSS) vulnerability in the Tutor LMS WordPress plugin allows attackers to inject malicious scripts into web pages. When users view affected pages, the scripts execute ...

CVE-2024-37266

MEDIUM CVSS 4.9 Jul 9, 2024

This path traversal vulnerability in Tutor LMS WordPress plugin allows attackers to access files outside the intended directory. It affects all Tutor LMS installations from unknown versions up to 2.7....

CVE-2024-5438

MEDIUM CVSS 4.3 Jun 7, 2024

This vulnerability allows authenticated attackers with Instructor-level access or higher in Tutor LMS WordPress plugin to delete arbitrary quiz attempts due to insufficient validation of user-controll...

CVE-2024-4279

MEDIUM CVSS 6.5 May 16, 2024

This vulnerability allows authenticated attackers with Instructor-level permissions or higher in Tutor LMS WordPress plugin to delete any course without proper authorization. It affects WordPress site...

CVE-2024-3553

MEDIUM CVSS 6.5 May 2, 2024

This vulnerability in Tutor LMS WordPress plugin allows unauthenticated attackers to enable user registration on WordPress sites where it was previously disabled. It affects all Tutor LMS plugin versi...