Tutor LMS – eLearning and online course solution
tutor · eklenti
Tutor LMS – eLearning and online course solution için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
64 bilinen açık
1 kritik · 5 kayıt için istismar kodu yayımlanmış · son kayıt 22 Eyl 2026
Güvenlik açıkları
- Kritik 9.8
WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection
- Yüksek 8.8
Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution
- Yüksek 8.8
Tutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection
- Yüksek 8.8
WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerability
- Yüksek 8.8
WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerability
- Yüksek 8.8
WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities
- Yüksek 8.8
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
- Yüksek 8.8
WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection
- Yüksek 8.8
WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL Injection
- Yüksek 8.1
Tutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion
- Yüksek 7.6
WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection Vulnerability
- Yüksek 7.5
Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter
- Yüksek 7.5
Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code
- Yüksek 7.5
Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter
- Yüksek 7.5
CVE-2023-3133→ 2.2.1
Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API
- Yüksek 7.2
WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerability
- Yüksek 7.2
WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerability
- Yüksek 7.2
WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerability
- Yüksek 7.2
Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection
- Orta 6.5
Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter
- Orta 6.5
Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters
- Orta 6.5
Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array
- Orta 6.5
WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability
- Orta 6.5
WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability
- Orta 6.5
Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter
- Orta 6.5
WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability
- Orta 6.5
WordPress Tutor LMS plugin <= 3.9.5 - Broken Access Control vulnerability
- Orta 6.5
Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details
- Orta 6.5
Tutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL Injection
- Orta 6.5
Tutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course Deletion
- Orta 6.5
Tutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options Update
- Orta 6.4
Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title
- Orta 6.1
Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters
- Orta 6.1
CVE-2021-24873→ 1.9.11
Tutor LMS < 1.9.11 - Reflected Cross-Site Scripting
- Orta 5.4
WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability
- Orta 5.4
Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment
- Orta 5.4
Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion
- Orta 5.4
Tutor LMS Pro – eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments
- Orta 5.4
WordPress Tutor LMS plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerability
- Orta 5.4
Tutor LMS – eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' Shortcode
- Orta 5.3
Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter
- Orta 5.3
Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order
- Orta 5.3
Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action
- Orta 5.3
Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update
- Orta 5.3
Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration
- Orta 4.9
Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter
- Orta 4.9
Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter
- Orta 4.8
WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerability
- Orta 4.8
WordPress Tutor LMS Plugin <= 2.2.4 is vulnerable to Cross Site Scripting (XSS)
- Orta 4.3
Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Paramete
- Orta 4.3
Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter
- Orta 4.3
Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification
- Orta 4.3
Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion
- Orta 4.3
Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass
- Orta 4.3
Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification
- Orta 4.3
Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure
- Orta 4.3
WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerability
- Orta 4.3
Tutor LMS <= 2.7.4 - Cross-Site Request Forgery via 'addon_enable_disable'
- Orta 4.3
Tutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion
- Orta 4.3
Tutor LMS – eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase
- Orta 4.3
Tutor LMS – eLearning and online course solution <= 2.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
- Orta 4.3
Tutor LMS <= 2.6.0 - Missing Authorization
- Düşük 3.8
WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability
- Düşük 3.5
Tutor LMS <= 2.6.0 - Authenticated(Student+) HTML Injection via Q&A