Skip to main content

Vendor/product archive

themeum / tutor_lms CVEs

Beta · best-effort

49 CVEs tagged to themeum / tutor_lms1 Critical, 16 High, 31 Medium, 1 Low, 0 Unrated.

CVE-2025-6680

Published Oct 25, 2025

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3. This makes i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11564

Published Oct 25, 2025

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check while verifying webh…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10400

Published Nov 21, 2024

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10393

Published Nov 21, 2024

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43142

Published Nov 1, 2024

Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2919

Published Sep 10, 2024

The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5784

Published Aug 30, 2024

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39645

Published Aug 26, 2024

Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43282

Published Aug 18, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43231

Published Aug 12, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37947

Published Jul 20, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37266

Published Jul 9, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a thro…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37256

Published Jul 9, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.1.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25799

Published Jun 11, 2024

Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5438

Published Jun 7, 2024

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4902

Published Jun 7, 2024

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions up to, and includ…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4352

Published May 16, 2024

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_mate…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4351

Published May 16, 2024

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' fun…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4222

Published May 16, 2024

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4223

Published May 16, 2024

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4318

Published May 16, 2024

The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4279

Published May 16, 2024

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and inc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3553

Published May 2, 2024

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3994

Published Apr 25, 2024

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tutor_instructor_list' shortcode in all ve…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1503

Published Mar 21, 2024

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to m…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 49 CVEsPage 1 of 2