Themeum

Tutor Lms

77 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 82.46%
  • Veröffentlicht 21.11.2024 11:15:16
  • Zuletzt bearbeitet 23.01.2025 17:01:14

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...

  • EPSS 0.56%
  • Veröffentlicht 21.11.2024 11:15:16
  • Zuletzt bearbeitet 23.01.2025 17:04:21

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible ...

  • EPSS 0.4%
  • Veröffentlicht 01.11.2024 15:15:39
  • Zuletzt bearbeitet 04.04.2025 17:42:30

Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7.3.

  • EPSS 0.22%
  • Veröffentlicht 10.09.2024 10:15:05
  • Zuletzt bearbeitet 26.09.2024 21:59:24

The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for unauthenti...

  • EPSS 0.36%
  • Veröffentlicht 30.08.2024 04:15:08
  • Zuletzt bearbeitet 11.07.2025 19:58:55

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and inc...

  • EPSS 0.19%
  • Veröffentlicht 26.08.2024 21:15:23
  • Zuletzt bearbeitet 18.09.2024 16:46:57

Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

  • EPSS 0.44%
  • Veröffentlicht 18.08.2024 22:15:10
  • Zuletzt bearbeitet 22.01.2025 21:59:38

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

  • EPSS 0.3%
  • Veröffentlicht 12.08.2024 21:15:32
  • Zuletzt bearbeitet 22.01.2025 22:10:37

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.3.

  • EPSS 0.35%
  • Veröffentlicht 20.07.2024 09:15:06
  • Zuletzt bearbeitet 03.02.2025 15:36:35

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.2.

  • EPSS 0.62%
  • Veröffentlicht 09.07.2024 10:15:04
  • Zuletzt bearbeitet 21.11.2024 09:23:30

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a through 2.7.1.