İçeriğe atla
Noroxi

Tutor LMS – eLearning and online course solution

tutor · eklenti

Tutor LMS – eLearning and online course solution için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

64 bilinen açık

1 kritik · 5 kayıt için istismar kodu yayımlanmış · son kayıt 22 Eyl 2026

Güvenlik açıkları

  • CVE-2023-25700

    WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection

    Kritik 9.8
  • CVE-2026-78175

    Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution

    Yüksek 8.8
  • CVE-2025-6184

    Tutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection

    Yüksek 8.8
  • CVE-2024-43142

    WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerability

    Yüksek 8.8
  • CVE-2024-39645

    WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerability

    Yüksek 8.8
  • CVE-2023-25799

    WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities

    Yüksek 8.8
  • CVE-2024-1751

    Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection

    Yüksek 8.8
  • CVE-2023-25990

    WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection

    Yüksek 8.8
  • CVE-2023-25800

    WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL Injection

    Yüksek 8.8
  • CVE-2026-1375

    Tutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion

    Yüksek 8.1
  • CVE-2025-58993

    WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection Vulnerability

    Yüksek 7.6
  • CVE-2026-3360

    Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter

    Yüksek 7.5
  • CVE-2025-13673

    Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code

    Yüksek 7.5
  • CVE-2024-10400

    Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter

    Yüksek 7.5
  • CVE-2023-3133→ 2.2.1

    Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API

    Yüksek 7.5
  • CVE-2024-43282

    WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerability

    Yüksek 7.2
  • CVE-2024-37266

    WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerability

    Yüksek 7.2
  • CVE-2024-37256

    WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerability

    Yüksek 7.2
  • CVE-2024-4902

    Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection

    Yüksek 7.2
  • CVE-2026-89333

    Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter

    Orta 6.5
  • CVE-2026-16759

    Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters

    Orta 6.5
  • CVE-2026-15022

    Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array

    Orta 6.5
  • CVE-2026-57694

    WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability

    Orta 6.5
  • CVE-2026-40743

    WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2026-6080

    Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter

    Orta 6.5
  • CVE-2025-32223

    WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability

    Orta 6.5
  • CVE-2026-23799

    WordPress Tutor LMS plugin <= 3.9.5 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2025-13679

    Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details

    Orta 6.5
  • CVE-2024-4318

    Tutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL Injection

    Orta 6.5
  • CVE-2024-4279

    Tutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course Deletion

    Orta 6.5
  • CVE-2024-3553

    Tutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options Update

    Orta 6.5
  • CVE-2026-13443

    Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title

    Orta 6.4
  • CVE-2026-89081

    Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters

    Orta 6.1
  • CVE-2021-24873→ 1.9.11

    Tutor LMS < 1.9.11 - Reflected Cross-Site Scripting

    Orta 6.1
  • CVE-2026-40740

    WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability

    Orta 5.4
  • CVE-2026-3358

    Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment

    Orta 5.4
  • CVE-2026-0548

    Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion

    Orta 5.4
  • CVE-2025-6639

    Tutor LMS Pro – eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments

    Orta 5.4
  • CVE-2024-43231

    WordPress Tutor LMS plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerability

    Orta 5.4
  • CVE-2024-3994

    Tutor LMS – eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' Shortcode

    Orta 5.4
  • CVE-2026-6965

    Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter

    Orta 5.3
  • CVE-2026-5502

    Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order

    Orta 5.3
  • CVE-2026-1371

    Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action

    Orta 5.3
  • CVE-2025-11564

    Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update

    Orta 5.3
  • CVE-2024-10393

    Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration

    Orta 5.3
  • CVE-2026-15444

    Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter

    Orta 4.9
  • CVE-2026-10736

    Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter

    Orta 4.9
  • CVE-2024-37947

    WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerability

    Orta 4.8
  • CVE-2023-49829

    WordPress Tutor LMS Plugin <= 2.2.4 is vulnerable to Cross Site Scripting (XSS)

    Orta 4.8
  • CVE-2026-18439

    Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Paramete

    Orta 4.3
  • CVE-2026-88944

    Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter

    Orta 4.3
  • CVE-2026-3371

    Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification

    Orta 4.3
  • CVE-2025-13935

    Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion

    Orta 4.3
  • CVE-2025-13934

    Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass

    Orta 4.3
  • CVE-2025-13628

    Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification

    Orta 4.3
  • CVE-2025-6680

    Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure

    Orta 4.3
  • CVE-2025-32230

    WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerability

    Orta 4.3
  • CVE-2023-2919

    Tutor LMS <= 2.7.4 - Cross-Site Request Forgery via 'addon_enable_disable'

    Orta 4.3
  • CVE-2024-5438

    Tutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion

    Orta 4.3
  • CVE-2024-1503

    Tutor LMS – eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase

    Orta 4.3
  • CVE-2024-1502

    Tutor LMS – eLearning and online course solution <= 2.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion

    Orta 4.3
  • CVE-2024-1133

    Tutor LMS <= 2.6.0 - Missing Authorization

    Orta 4.3
  • CVE-2025-47555

    WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability

    Düşük 3.8
  • CVE-2024-1128

    Tutor LMS <= 2.6.0 - Authenticated(Student+) HTML Injection via Q&A

    Düşük 3.5

← Dizine dön