themeum tutor lms是themeum公司开源的一款在线学习管理系统。 WordPress Tutor LMS 3.9.13之前版本存在授权问题漏洞,该漏洞源于未验证目标测验尝试的所有权,允许具有订阅者级别及以上访问权限的已验证用户修改和强制完成其他学生的测验尝试,覆盖其记录的成绩和通过/失败结果。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12275 | Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content | |
| CVE-2026-12397 | WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR | |
| CVE-2026-12582 | Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id | |
| CVE-2026-12396 | WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection | |
| CVE-2026-11964 | User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verifica | |
| CVE-2026-12081 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object | |
| CVE-2026-12273 | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation | |
| CVE-2026-12274 | Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR | |
| CVE-2026-11963 | User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier M | |
| CVE-2026-10551 | Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library |
No comments yet