themeum Vulnerabilities and Affected Products
Vulnerabilities associated with tutor_lms.
Products
Clear product- Tutor LMS – eLearning and online course solution37 vulnerabilities
- Tutor LMS19 vulnerabilities
- tutor_lms16 vulnerabilities
- Kirki – Freeform Page Builder, Website Builder & Customizer9 vulnerabilities
- Tutor LMS Pro9 vulnerabilities
- WP Crowdfunding9 vulnerabilities
- Kirki7 vulnerabilities
- Tutor LMS Elementor Addons6 vulnerabilities
- Qubely5 vulnerabilities
- Droip2 vulnerabilities
- Qubely – Advanced Gutenberg Blocks2 vulnerabilities
- Tutor LMS – Migration Tool2 vulnerabilities
- Right Way1 vulnerability
- Skillate1 vulnerability
- Tutor LMS BunnyNet Integration1 vulnerability
- tutor_lms_pro1 vulnerability
- tutorlms-migrationtool1 vulnerability
- WP Mega Menu1 vulnerability
- WP Page Builder (WordPress plugin)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-10400HIGH | Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filterThe Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | CVSS7.5v3.1 | EPSS82.5% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-10393MEDIUM | Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User RegistrationThe Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled. | CVSS5.3v3.1 | EPSS0.563% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5438MEDIUM | Tutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt DeletionThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary quiz attempts. CWE-639Jun 7, 2024 | CVSS4.3v3.1 | EPSS0.343% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4902HIGH | Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL InjectionThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive infor… CWE-89Jun 7, 2024 | CVSS7.2v3.1 | EPSS0.495% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4351HIGH | Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege EscalationThe Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account. | CVSS8.8v3.1 | EPSS1.01% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4318HIGH | Tutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL InjectionThe Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CWE-89May 16, 2024 | CVSS8.8v3.1 | EPSS0.511% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4279MEDIUM | Tutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course DeletionThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow authenticated attackers, with Instructor-level permissions and above, to delete any course. CWE-639May 16, 2024 | CVSS6.5v3.1 | EPSS0.418% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3553MEDIUM | Tutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options UpdateThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices function in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to enable user registration on sites that may have it disabled. CWE-862May 2, 2024 | CVSS6.5v3.1 | EPSS0.466% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1751HIGH | Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL InjectionThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber/student access or higher, to append additional SQL queries into already existing queries that can be used to extract se… | CVSS8.8v3.1 | EPSS3.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-25700HIGH | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10. CWE-89Nov 3, 2023 | CVSS8.2v3.1 | EPSS0.756% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-25800HIGH | WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0. CWE-89Nov 3, 2023 | CVSS8.1v3.1 | EPSS0.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-25990HIGH | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10. CWE-89Nov 3, 2023 | CVSS7.1v3.1 | EPSS0.679% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24184HIGH | Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege EscalationSeveral AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions. | CVSS8.8v3.1 | EPSS1.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24186MEDIUM | Tutor LMS < 1.8.3 - SQL Injection via tutor_answering_quiz_question/get_answer_by_idThe tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students. CWE-89Apr 5, 2021 | CVSS6.5v3.1 | EPSS1.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24183MEDIUM | Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_question_formThe tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students. CWE-89Apr 5, 2021 | CVSS6.5v3.1 | EPSS1.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24182MEDIUM | Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_answers_by_questionThe tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students. CWE-89Apr 5, 2021 | CVSS6.5v3.1 | EPSS1.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |