themeum Vulnerabilities and Affected Products
Vulnerabilities associated with Tutor LMS.
Products
Clear product- Tutor LMS – eLearning and online course solution37 vulnerabilities
- Tutor LMS19 vulnerabilities
- tutor_lms16 vulnerabilities
- Kirki – Freeform Page Builder, Website Builder & Customizer9 vulnerabilities
- Tutor LMS Pro9 vulnerabilities
- WP Crowdfunding9 vulnerabilities
- Kirki7 vulnerabilities
- Tutor LMS Elementor Addons6 vulnerabilities
- Qubely5 vulnerabilities
- Droip2 vulnerabilities
- Qubely – Advanced Gutenberg Blocks2 vulnerabilities
- Tutor LMS – Migration Tool2 vulnerabilities
- Right Way1 vulnerability
- Skillate1 vulnerability
- Tutor LMS BunnyNet Integration1 vulnerability
- tutor_lms_pro1 vulnerability
- tutorlms-migrationtool1 vulnerability
- WP Mega Menu1 vulnerability
- WP Page Builder (WordPress plugin)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57694MEDIUM | WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13. CWE-639Jul 13, 2026 | CVSS6.5v3.1 | EPSS0.237% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40743MEDIUM | WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions. CWE-862Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40740MEDIUM | WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7. CWE-862Apr 15, 2026 | CVSS5.4v3.1 | EPSS0.177% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32223MEDIUM | WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4. CWE-639Mar 19, 2026 | CVSS6.5v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-23799MEDIUM | WordPress Tutor LMS plugin <= 3.9.5 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.5. CWE-862Mar 5, 2026 | CVSS6.5v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4. CWE-639Jan 22, 2026 | CVSS3.8v3.1 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-58993HIGH | WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS tutor allows SQL Injection.This issue affects Tutor LMS: from n/a through <= 3.7.4. CWE-89Sep 9, 2025 | CVSS7.6v3.1 | EPSS0.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32230MEDIUM | WordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerabilityImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS tutor.This issue affects Tutor LMS: from n/a through <= 3.4.0. CWE-80Apr 10, 2025 | CVSS4.3v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43142MEDIUM | WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7.3. CWE-862Nov 1, 2024 | CVSS4.3v3.1 | EPSS0.403% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-39645MEDIUM | WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2. CWE-352Aug 26, 2024 | CVSS5.4v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43282HIGH | WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2. CWE-89Aug 18, 2024 | CVSS7.6v3.1 | EPSS0.439% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43231MEDIUM | WordPress Tutor LMS plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.3. CWE-79Aug 12, 2024 | CVSS6.5v3.1 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37947MEDIUM | WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.2. CWE-79Jul 20, 2024 | CVSS5.9v3.1 | EPSS0.354% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37266MEDIUM | WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a through 2.7.1. CWE-22Jul 9, 2024 | CVSS4.9v3.1 | EPSS0.618% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37256HIGH | WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.1. CWE-89Jul 9, 2024 | CVSS7.6v3.1 | EPSS0.577% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-25799HIGH | WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilitiesMissing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8. CWE-862Jun 11, 2024 | CVSS8.3v3.1 | EPSS0.458% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-25700HIGH | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10. CWE-89Nov 3, 2023 | CVSS8.2v3.1 | EPSS0.756% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-25800HIGH | WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0. CWE-89Nov 3, 2023 | CVSS8.1v3.1 | EPSS0.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-25990HIGH | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10. CWE-89Nov 3, 2023 | CVSS7.1v3.1 | EPSS0.679% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |