CVE · Medium

CVE-2026-15444 — Tutor LMS – eLearning and online course solution [tutor] < 4.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15444 Tutor LMS – eLearning and online course solution [tutor] < 4.0.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 4.0.2 4.0.2 2026-07-27

CVE-2026-15444

Tutor LMS plugin for WordPress contains a security flaw in versions up to 4.0.1 that allows malicious users with admin privileges or higher to inject arbitrary SQL code through the coupon_code parameter, potentially leading to unauthorized data extraction from the database. This vulnerability stems from inadequate protection against user input and insufficient sanitization of existing SQL queries. As a result, attackers can exploit this weakness to extract sensitive information from the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.