Themeum

Tutor Lms

84 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 08.10.2026 13:14:10
  • Zuletzt bearbeitet 08.10.2026 17:24:11

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leveraging Race Conditions.This issue affects Tutor LMS: from n/a through 4.1.1.

  • EPSS 0.25%
  • Veröffentlicht 22.09.2026 07:41:12
  • Zuletzt bearbeitet 23.09.2026 19:17:29

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation that nested ques...

  • EPSS 0.22%
  • Veröffentlicht 19.09.2026 02:27:11
  • Zuletzt bearbeitet 21.09.2026 13:33:33

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escapin...

  • EPSS 0.28%
  • Veröffentlicht 19.09.2026 02:27:10
  • Zuletzt bearbeitet 21.09.2026 13:33:33

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly verifying that a user is authorized to perform an acti...

  • EPSS 0.27%
  • Veröffentlicht 19.09.2026 02:27:07
  • Zuletzt bearbeitet 21.09.2026 13:33:33

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user controlled key....

Medienbericht
  • EPSS 0.59%
  • Veröffentlicht 12.09.2026 07:39:15
  • Zuletzt bearbeitet 15.09.2026 15:17:21

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. T...

  • EPSS 0.43%
  • Veröffentlicht 28.08.2026 03:39:35
  • Zuletzt bearbeitet 28.08.2026 16:17:07

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. Th...

  • EPSS 0.29%
  • Veröffentlicht 28.07.2026 11:32:49
  • Zuletzt bearbeitet 28.07.2026 16:07:15

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter a...

  • EPSS 0.34%
  • Veröffentlicht 16.07.2026 07:51:03
  • Zuletzt bearbeitet 18.07.2026 03:16:34

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and ...

  • EPSS 0.24%
  • Veröffentlicht 13.07.2026 08:41:24
  • Zuletzt bearbeitet 13.07.2026 16:57:56

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.