Themeum

Tutor Lms

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.18%
  • Veröffentlicht 16.05.2024 10:15:10
  • Zuletzt bearbeitet 08.04.2026 19:21:35

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the...

  • EPSS 1.02%
  • Veröffentlicht 16.05.2024 10:15:09
  • Zuletzt bearbeitet 08.04.2026 18:21:46

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possib...

  • EPSS 0.33%
  • Veröffentlicht 16.05.2024 10:15:08
  • Zuletzt bearbeitet 08.04.2026 18:21:43

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for un...

  • EPSS 0.52%
  • Veröffentlicht 16.05.2024 09:15:15
  • Zuletzt bearbeitet 08.04.2026 19:21:34

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauth...

  • EPSS 0.51%
  • Veröffentlicht 16.05.2024 06:15:11
  • Zuletzt bearbeitet 08.04.2026 18:21:45

The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

  • EPSS 0.42%
  • Veröffentlicht 16.05.2024 06:15:10
  • Zuletzt bearbeitet 08.04.2026 18:21:44

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing val...

  • EPSS 0.47%
  • Veröffentlicht 02.05.2024 17:15:26
  • Zuletzt bearbeitet 08.04.2026 19:21:22

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices function in all versions up to, and including, 2.6.2. This makes it pos...

  • EPSS 0.39%
  • Veröffentlicht 25.04.2024 10:15:09
  • Zuletzt bearbeitet 08.04.2026 18:21:39

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tutor_instructor_list' shortcode in all versions up to, and including, 2.6.2 due to insufficient input sanitizati...

  • EPSS 0.22%
  • Veröffentlicht 21.03.2024 02:51:43
  • Zuletzt bearbeitet 08.04.2026 17:18:21

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the erase_tutor_data() function...

  • EPSS 0.43%
  • Veröffentlicht 21.03.2024 02:51:43
  • Zuletzt bearbeitet 08.04.2026 18:20:41

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. This makes...