Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Tutor LMS — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in Tutor LMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Tutor LMS, a WordPress learning management system plugin, focusing on a specific class of security weaknesses identified by the Common Weakness Enumeration. The collection gathers reported flaws affecting this product over a defined historical period, capturing both high-severity and lower-risk issues within the selected scope. Readers can use this interface to track the vendor’s security advisories, analyze the prevalence of particular weakness types, and review the product’s vulnerability history. By examining the patterns in these records, users gain insight into recurring failure modes and the timeline of remediation efforts. The data is organized to support rapid assessment of risk trends and comparison across different vulnerability categories associated with this specific educational software component.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-85572 Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure - - 2026-09-16
CVE-2026-85569 Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification - - 2026-09-16
CVE-2026-19092 Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing 9.8 Critical 2026-08-27
CVE-2026-19094 Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters - - 2026-08-26
CVE-2026-19093 Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path - - 2026-08-22
CVE-2026-14187 Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure via IDOR - - 2026-08-22
CVE-2026-14306 Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass 4.3 Medium 2026-08-06
CVE-2026-14310 Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection - - 2026-07-30
CVE-2026-57694 WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2026-07-13
CVE-2026-12275 Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration - - 2026-07-13
CVE-2026-12274 Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR - - 2026-07-13
CVE-2026-12271 Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR - - 2026-07-13
CVE-2026-12273 Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation - - 2026-07-13
CVE-2026-40743 WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-06-15
CVE-2026-40740 WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability CWE-862 5.4 Medium 2026-04-15
CVE-2025-32223 WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2026-03-19
CVE-2026-23799 WordPress Tutor LMS plugin <= 3.9.5 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-03-05
CVE-2025-47555 WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability CWE-639 3.8 Low 2026-01-22
CVE-2025-58993 WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection Vulnerability CWE-89 7.6 High 2025-09-09
CVE-2025-32230 WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerability CWE-80 4.3 Medium 2025-04-10
CVE-2024-43142 WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-11-01
CVE-2024-39645 WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium 2024-08-26
CVE-2024-43282 WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerability CWE-89 7.6 High 2024-08-18
CVE-2024-43231 WordPress Tutor LMS plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-08-12
CVE-2024-37947 WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-07-20
CVE-2024-37266 WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerability CWE-22 4.9 Medium 2024-07-09
CVE-2024-37256 WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerability CWE-89 7.6 High 2024-07-09
CVE-2023-25799 WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities CWE-862 8.3 High 2024-06-11
CVE-2023-25700 WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection CWE-89 8.2 High 2023-11-03
CVE-2023-25800 WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL Injection CWE-89 8.1 High 2023-11-03

All 34 known CVE vulnerabilities affecting Tutor LMS with full Chinese analysis, references, and POCs where available.