Pricing
Case studies
Login
Start trial
Tutor LMS
Themeum
Developer
3.9.8
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
56 patched
21 Mitigation rules
Insecure Direct Object References (IDOR) vulnerability
<= 3.9.4
16/03/2026
Unauthenticated SQL Injection via coupon_code vulnerability
<= 3.9.6
02/03/2026
Broken Access Control vulnerability
<= 3.9.5
25/02/2026
Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion vulnerability
<= 3.9.5
03/02/2026
Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action vulnerability
<= 3.9.5
02/02/2026
Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion vulnerability
<= 3.9.2
30/01/2026
WordPress Tutor LMS - eLearning and online course solution plugin <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion vulnerability
<= 3.9.4
20/01/2026
WordPress Tutor LMS - eLearning and online course solution plugin <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification vulnerability
<= 3.9.3
08/01/2026
WordPress Tutor LMS - eLearning and online course solution plugin <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass vulnerability
<= 3.9.3
08/01/2026
Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details vulnerability
<= 3.9.3
08/01/2026
Insecure Direct Object References (IDOR) vulnerability
<= 3.9.4
02/01/2026
Missing Authorization to Sensitive Information Exposure vulnerability
<= 3.8.3
25/10/2025
Missing Authorization to Unauthenticated Payment Status Update vulnerability
<= 3.8.3
25/10/2025
SQL Injection Vulnerability
<= 3.7.4
09/09/2025
HTML Injection vulnerability
<= 3.4.0
07/04/2025
Unauthenticated SQL Injection via rating_filter vulnerability
<= 2.7.6
21/11/2024
User Registration Setting Bypass to Unauthorized User Registration vulnerability
<= 2.7.6
21/11/2024
Cross-Site Request Forgery via 'addon_enable_disable' vulnerability
<= 2.7.4
10/09/2024
SQL Injection vulnerability
<= 2.7.2
16/08/2024
Cross Site Scripting (XSS) vulnerability
<= 2.7.3
09/08/2024
Broken Access Control vulnerability
<= 2.7.3
07/08/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 2.7.2
01/08/2024
Cross Site Scripting (XSS) vulnerability
<= 2.7.2
10/07/2024
Path Traversal vulnerability
<= 2.7.1
27/06/2024
SQL Injection vulnerability
<= 2.7.1
27/06/2024
Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion vulnerability
<= 2.7.1
07/06/2024
Missing Authorization vulnerability
<= 2.7.0
16/05/2024
Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course Deletion vulnerability
<= 2.7.0
16/05/2024
Authenticated (Instructor+) SQL Injection vulnerability
<= 2.7.0
16/05/2024
Missing Authorization to Unauthenticated Limited Options Update vulnerability
<= 2.6.2
29/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' Shortcode vulnerability
<= 2.6.2
25/04/2024
Cross-Site Request Forgery to Plugin Deactivation and Data Erase vulnerability
<= 2.6.1
12/03/2024
Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion vulnerability
<= 2.6.1
12/03/2024
Authenticated (Subscriber+) SQL Injection vulnerability
<= 2.6.1
12/03/2024
Missing Authorization vulnerability
<= 2.6.0
21/02/2024
Authenticated(Student+) HTML Injection via Q&A vulnerability
<= 2.6.0
21/02/2024
Cross Site Scripting (XSS) vulnerability
<= 2.2.4
05/12/2023
Subscriber+ Stored Cross-Site Scripting vulnerability
< 2.3.0
17/10/2023
Unauthenticated Access to Tutor LMS Lesson Resources via REST API vulnerability
< 2.2.1
22/06/2023
Unauthenticated SQL Injection vulnerability
<= 2.1.10
30/05/2023
Multiple Student+ SQL Injection vulnerability
<= 2.2.0
30/05/2023
Multiple Tutor Instructor+ SQL Injection vulnerability
<= 2.1.10
30/05/2023
Multiple Broken Access Control vulnerabilities
<= 2.1.8
24/05/2023
Reflected Cross-Site Scripting (XSS) vulnerability
< 2.0.10
12/01/2023
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.0.9
26/09/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.9.12
10/01/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 1.9.11
27/12/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.9.11
27/12/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.9.10
19/10/2021
Multiple Stored Cross-Site Scripting (XSS) vulnerabilities
<= 1.9.8
20/09/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.9.5
09/08/2021
Authenticated Local File Inclusion vulnerability
<= 1.8.7
05/04/2021
Multiple Blind/Time-based SQL Injection (SQLi) vulnerabilities
<= 1.7.6
15/03/2021
Multiple Union SQL Injection (SQLi) vulnerabilities
<= 1.8.2
15/03/2021
Unprotected AJAX Action to Privilege Escalation vulnerability
<= 1.7.6
15/03/2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 1.5.2
04/02/2020