VulnSea

tutor_lms_elearning_and_online_course_solution vulnerabilities

CVEs whose affected-version data names the tutor_lms_elearning_and_online_course_solution package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-89333Medium· 6.5
2d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.27%via NVD
CVE-2026-89081Medium· 6.1
2d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and o…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and o…

Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.21%via NVD
CVE-2026-88944Medium· 4.3
2d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly verifying that a user is authorized to pe…

Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.28%via NVD
CVE-2026-78175High· 8.8
1w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…

Twilightthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.59%via NVD
tutor_lms_elearning_and_online_course_solution vulnerabilities (CVEs) · VulnSea