themeum tutor lms是themeum公司开源的一款在线学习管理系统。 WordPress Tutor LMS 3.9.13之前版本存在权限许可和访问控制问题漏洞,该漏洞源于在处理评论创建时未执行任何授权或目标验证,并将评论存储为预先批准状态,可能导致经过身份验证且具备订阅者级或更高级别访问权限的用户发布包含任意HTML和链接的自动批准评论,绕过评论审核队列。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12275 | Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content | |
| CVE-2026-12397 | WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR | |
| CVE-2026-12582 | Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id | |
| CVE-2026-12396 | WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection | |
| CVE-2026-11964 | User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verifica | |
| CVE-2026-12081 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object | |
| CVE-2026-12271 | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR | |
| CVE-2026-12274 | Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR | |
| CVE-2026-11963 | User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier M | |
| CVE-2026-10551 | Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library |
No comments yet