Themeum Tutor Lms vulnerabilities
56 known vulnerabilities affecting themeum/tutor_lms.
Total CVEs
56
CISA KEV
0
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL2HIGH18MEDIUM33LOW3
Vulnerabilities
Page 1 of 3
CVE-2024-10400P1HIGHCVSS 7.5ExploitedPoC≤ 2.7.62024-11-21
CVE-2024-10400 [HIGH] CWE-89 CVE-2024-10400: The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int
nvd
CVE-2024-4351P1HIGHCVSS 8.8Exploitedfixed in 2.7.12024-05-16
CVE-2024-4351 [HIGH] CWE-89 CVE-2024-4351: The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existin
nvd
CVE-2021-24182P2MEDIUMCVSS 6.5Exploitedfixed in 1.8.32021-04-05
CVE-2021-24182 [MEDIUM] CWE-89 CVE-2021-24182: The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online
The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
nvd
CVE-2021-24183P2MEDIUMCVSS 6.5Exploitedfixed in 1.8.32021-04-05
CVE-2021-24183 [MEDIUM] CWE-89 CVE-2021-24183: The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online cours
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
nvd
CVE-2021-24186P2MEDIUMCVSS 6.5Exploitedfixed in 1.8.32021-04-05
CVE-2021-24186 [MEDIUM] CWE-89 CVE-2021-24186: The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
nvd
CVE-2021-24184P2HIGHCVSS 8.8Exploitedfixed in 1.7.72021-04-05
CVE-2021-24184 [HIGH] CWE-862 CVE-2021-24184: Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin befo
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.
nvd
CVE-2024-1751P2HIGHCVSS 8.8PoCfixed in 2.6.22024-03-13
CVE-2024-1751 [HIGH] CWE-89 CVE-2024-1751: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-base
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att
nvd
CVE-2020-8615P3MEDIUMCVSS 6.5PoCfixed in 1.5.32020-02-04
CVE-2020-8615 [MEDIUM] CWE-352 CVE-2020-8615: A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker ap
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
nvd
CVE-2023-25700P3CRITICALCVSS 9.8≤ 2.1.10≥ n/a, ≤ 2.1.102023-11-03
CVE-2023-25700 [CRITICAL] CWE-89 CVE-2023-25700: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.
nvd
CVE-2024-4223P3CRITICALCVSS 9.8fixed in 2.7.12024-05-16
CVE-2024-4223 [CRITICAL] CWE-862 CVE-2024-4223: The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of dat
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.
nvd
CVE-2024-4352P3HIGHCVSS 8.8fixed in 2.7.12024-05-16
CVE-2024-4352 [HIGH] CWE-862 CVE-2024-4352: The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the ‘year’ parameter of that function due to insufficient escaping on the user supplied parameter and lack o
nvd
CVE-2023-25990P3HIGHCVSS 8.8≤ 2.1.10≥ n/a, ≤ 2.1.102023-11-03
CVE-2023-25990 [HIGH] CWE-89 CVE-2023-25990: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.
nvd
CVE-2023-0236P3MEDIUMCVSS 6.1PoCfixed in 2.0.102023-02-06
CVE-2023-0236 [MEDIUM] CWE-79 CVE-2023-0236: The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
nvd
CVE-2023-25800P3HIGHCVSS 8.8≤ 2.2.0≥ n/a, ≤ 2.2.02023-11-03
CVE-2023-25800 [HIGH] CWE-89 CVE-2023-25800: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0.
nvd
CVE-2023-25799P3HIGHCVSS 8.8fixed in 2.1.9≥ n/a, ≤ 2.1.82024-06-11
CVE-2023-25799 [HIGH] CWE-862 CVE-2023-25799: Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a thro
Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.
nvd
CVE-2024-43142P3HIGHCVSS 8.8fixed in 2.7.4≥ n/a, ≤ 2.7.32024-11-01
CVE-2024-43142 [HIGH] CWE-862 CVE-2024-43142: Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Ac
Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7.3.
nvd
CVE-2024-4222P3HIGHCVSS 8.2fixed in 2.7.12024-05-16
CVE-2024-4222 [HIGH] CWE-862 CVE-2024-4222: The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.
nvd
CVE-2023-3133P3HIGHCVSS 7.5fixed in 2.2.12023-07-04
CVE-2023-3133 [HIGH] CWE-639 CVE-2023-3133: The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST A
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
nvd
CVE-2024-37266P3HIGHCVSS 7.2fixed in 2.7.2≥ n/a, ≤ 2.7.12024-07-09
CVE-2024-37266 [HIGH] CWE-22 CVE-2024-37266: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Them
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a through 2.7.1.
nvd
CVE-2025-58993P3HIGHCVSS 7.6≤ 3.7.42025-09-09
CVE-2025-58993 [HIGH] CWE-89 CVE-2025-58993: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS tutor allows SQL Injection.This issue affects Tutor LMS: from n/a through <= 3.7.4.
nvd
1 / 3Next →