Home/Product/themeum tutor lms
Product

themeum tutor lms

49 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-6680
< 3.9.0
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all v
4.3MEDIUM
CVE-2025-11564
< 3.9.0
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due t
5.3MEDIUM
CVE-2024-10400
<= 2.7.6
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and
7.5HIGH
CVE-2024-10393
<= 2.7.6
The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is d
5.3MEDIUM
CVE-2024-43142
< 2.7.4
Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.T
4.3MEDIUM
CVE-2023-2919
< 2.7.5
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is du
4.3MEDIUM
CVE-2024-5784
< 2.7.3
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability
7.1HIGH
CVE-2024-39645
< 2.7.3
Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
5.4MEDIUM
CVE-2024-43282
< 2.7.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue
7.6HIGH
CVE-2024-43231
< 2.7.4
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS all
6.5MEDIUM
CVE-2024-37947
< 2.7.3
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS all
5.9MEDIUM
CVE-2024-37266
< 2.7.2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Trav
4.9MEDIUM
CVE-2024-37256
< 2.7.2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue
7.6HIGH
CVE-2023-25799
< 2.1.9
Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.
8.3HIGH
CVE-2024-5438
< 2.7.2
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all
4.3MEDIUM
CVE-2024-4902
< 2.7.2
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘cou
7.2HIGH
CVE-2024-4352
< 2.7.1
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a m
8.8HIGH
CVE-2024-4351
< 2.7.1
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a m
8.8HIGH
CVE-2024-4222
< 2.7.1
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a m
7.3HIGH
CVE-2024-4223
< 2.7.1
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missi
9.8CRITICAL
CVE-2024-4318
< 2.7.1
The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to
8.8HIGH
CVE-2024-4279
< 2.7.1
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arb
6.5MEDIUM
CVE-2024-3553
< 2.7.0
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due t
6.5MEDIUM
CVE-2024-3994
< 2.7.0
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu
5.4MEDIUM
CVE-2024-1503
< 2.6.2
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi
4.3MEDIUM
CVE-2024-1502
< 2.6.2
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a miss
5.4MEDIUM
CVE-2024-1751
< 2.6.2
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the questi
8.8HIGH
CVE-2024-1133
< 2.6.1
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restricted Q&A c
4.3MEDIUM
CVE-2024-1128
< 2.6.1
The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versions up to, a
5.4MEDIUM
CVE-2023-49829
<= 2.2.4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS - eLearnin
5.9MEDIUM
CVE-2023-25990
<= 2.1.10
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL
7.1HIGH
CVE-2023-25800
<= 2.2.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL
8.1HIGH
CVE-2023-25700
<= 2.1.10
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL
8.2HIGH
CVE-2023-4805
< 2.3.0
The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as sub
5.4MEDIUM
CVE-2023-3133
< 2.2.1
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthe
7.5HIGH
CVE-2023-0236
< 2.0.10
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting t
6.1MEDIUM
CVE-2022-2563
< 2.0.10
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such a
4.8MEDIUM
CVE-2021-25017
< 1.9.12
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an
6.1MEDIUM
CVE-2021-24873
< 1.9.11
The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the S
6.1MEDIUM
CVE-2021-24740
< 1.9.9
The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could
4.8MEDIUM
CVE-2021-24455
< 1.9.2
The Tutor LMS - eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcemen
5.4MEDIUM
CVE-2021-24242
< 1.8.8
The Tutor LMS - eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerabi
3.8LOW
CVE-2021-24186
< 1.8.3
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS - eLearning and online course solution WordPre
6.5MEDIUM
CVE-2021-24185
< 1.7.7
The tutor_place_rating AJAX action from the Tutor LMS - eLearning and online course solution WordPress plugin before 1.7.7 was vul
6.5MEDIUM
CVE-2021-24184
< 1.7.7
Several AJAX endpoints in the Tutor LMS - eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, all
8.8HIGH
CVE-2021-24183
< 1.8.3
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS - eLearning and online course solution WordPress plugin be
6.5MEDIUM
CVE-2021-24182
< 1.8.3
The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS - eLearning and online course solution WordPress plu
6.5MEDIUM
CVE-2021-24181
< 1.7.7
The tutor_mark_answer_as_correct AJAX action from the Tutor LMS - eLearning and online course solution WordPress plugin before 1.7
6.5MEDIUM
CVE-2020-8615
< 1.5.3
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instr
6.5MEDIUM
threatengine.sh