PLUGIN SECURITY
Is Tutor safe?
A complete WordPress LMS plugin to create any eLearning website easily.
What this plugin does
- Slug:
tutor - Author: Themeum
- 100000+ active installs
- 88/100 rating (588 reviews on wordpress.org)
- 4483404 all-time downloads
- On WordPress.org since 2019-02-06
courseeducationelearninglearning management systemlms
Maintenance status
- Latest known version: 4.0.4
- Last updated: 2026-08-21 1:29am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
82 known CVEs on file for Tutor.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-19092 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.6 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | Critical 9.8 | < 4.0.6 | 4.0.6 | 2026-08-27 | ⚠ update needed |
| CVE-2026-19094 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Unknown | < 4.0.6 | 4.0.6 | 2026-08-26 | ⚠ update needed |
| CVE-2026-14187 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.6 | Authorization Bypass Through User-Controlled Key | Low 2.7 | < 4.0.6 | 4.0.6 | 2026-08-22 | ⚠ update needed |
| CVE-2026-19093 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.6 | Files or Directories Accessible to External Parties | Medium 6.8 | < 4.0.6 | 4.0.6 | 2026-08-22 | ⚠ update needed |
| CVE-2026-14306 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.14 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 3.9.14 | 3.9.14 | 2026-08-06 | ✓ fixed in latest |
| CVE-2026-16759 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.6 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | Medium 6.5 | < 4.0.6 | 4.0.6 | 2026-07-30 | ⚠ update needed |
| CVE-2026-15444 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 4.0.2 | 4.0.2 | 2026-07-27 | ✓ fixed in latest |
| CVE-2026-14310 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.0 | Authorization Bypass Through User-Controlled Key | Unknown | < 4.0.0 | 4.0.0 | 2026-07-27 | ✓ fixed in latest |
+ 100 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-15022 | Tutor LMS – eLearning and online course solution [tutor] < 4.0.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 4.0.1 | 4.0.1 | 2026-07-15 | ✓ fixed in latest |
| CVE-2026-57694 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.14 | — | Medium 6.5 | < 3.9.14 | 3.9.14 | 2026-07-06 | ✓ fixed in latest |
| CVE-2026-13443 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.14 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.9.14 | 3.9.14 | 2026-06-30 | ✓ fixed in latest |
| CVE-2026-12275 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.13 | Improper Authentication | Unknown | < 3.9.13 | 3.9.13 | 2026-06-22 | ✓ fixed in latest |
| CVE-2026-12274 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.13 | Authorization Bypass Through User-Controlled Key | Unknown | < 3.9.13 | 3.9.13 | 2026-06-22 | ✓ fixed in latest |
| CVE-2026-12273 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.13 | Improper Access Control | Unknown | < 3.9.13 | 3.9.13 | 2026-06-22 | ✓ fixed in latest |
| CVE-2026-12271 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.13 | Authorization Bypass Through User-Controlled Key | Unknown | < 3.9.13 | 3.9.13 | 2026-06-22 | ✓ fixed in latest |
| CVE-2026-10736 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.12 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 3.9.12 | 3.9.12 | 2026-06-17 | ✓ fixed in latest |
| CVE-2026-6965 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.10 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 3.9.10 | 3.9.10 | 2026-05-12 | ✓ fixed in latest |
| CVE-2026-40743 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.8 | Missing Authorization | Medium 6.5 | < 3.9.8 | 3.9.8 | 2026-04-20 | ✓ fixed in latest |
| CVE-2026-6080 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.9 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 3.9.9 | 3.9.9 | 2026-04-16 | ✓ fixed in latest |
| CVE-2026-5502 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.9 | Missing Authorization | Medium 5.3 | < 3.9.9 | 3.9.9 | 2026-04-16 | ✓ fixed in latest |
| CVE-2025-32223 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.5 | Authorization Bypass Through User-Controlled Key | Medium 6.5 | < 3.9.5 | 3.9.5 | 2026-03-16 | ✓ fixed in latest |
| CVE-2026-40740 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.8 | — | Medium 5.4 | < 3.9.8 | 3.9.8 | 2026-03-15 | ✓ fixed in latest |
| CVE-2025-13673 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.7 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 3.9.7 | 3.9.7 | 2026-02-27 | ✓ fixed in latest |
| CVE-2026-23799 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.6 | Missing Authorization | Medium 6.5 | < 3.9.6 | 3.9.6 | 2026-02-25 | ✓ fixed in latest |
| CVE-2025-13935 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.4 | Missing Authorization | Medium 4.3 | < 3.9.4 | 3.9.4 | 2026-01-08 | ✓ fixed in latest |
| CVE-2025-13934 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.4 | Missing Authorization | Medium 4.3 | < 3.9.4 | 3.9.4 | 2026-01-08 | ✓ fixed in latest |
| CVE-2025-13628 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.4 | Missing Authorization | Medium 4.3 | < 3.9.4 | 3.9.4 | 2026-01-08 | ✓ fixed in latest |
| CVE-2025-13679 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.4 | Missing Authorization | Medium 6.5 | < 3.9.4 | 3.9.4 | 2026-01-07 | ✓ fixed in latest |
| CVE-2025-47555 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.5 | Authorization Bypass Through User-Controlled Key | Low 3.8 | < 3.9.5 | 3.9.5 | 2026-01-02 | ✓ fixed in latest |
| CVE-2025-11564 | Tutor LMS – eLearning and online course solution [tutor] < 3.9.0 | Missing Authorization | Medium 5.3 | < 3.9.0 | 3.9.0 | 2025-10-24 | ✓ fixed in latest |
| CVE-2025-58993 | Tutor LMS – eLearning and online course solution [tutor] < 3.8.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.6 | < 3.8.0 | 3.8.0 | 2025-09-09 | ✓ fixed in latest |
| CVE-2025-32230 | Tutor LMS – eLearning and online course solution [tutor] < 3.4.1 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 4.3 | < 3.4.1 | 3.4.1 | 2025-04-07 | ✓ fixed in latest |
| CVE-2024-10393 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.7 | Improper Access Control | Medium 5.3 | < 2.7.7 | 2.7.7 | 2024-11-20 | ✓ fixed in latest |
| CVE-2024-10400 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.7 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 2.7.7 | 2.7.7 | 2024-11-20 | ✓ fixed in latest |
| CVE-2023-2919 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.5 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.7.5 | 2.7.5 | 2024-09-09 | ✓ fixed in latest |
| CVE-2024-43282 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 2.7.3 | 2.7.3 | 2024-08-16 | ✓ fixed in latest |
| CVE-2024-43231 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.7.4 | 2.7.4 | 2024-08-09 | ✓ fixed in latest |
| CVE-2024-43142 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.4 | Missing Authorization | High 8.8 | < 2.7.4 | 2.7.4 | 2024-08-07 | ✓ fixed in latest |
| CVE-2024-39645 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.3 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 2.7.3 | 2.7.3 | 2024-08-01 | ✓ fixed in latest |
| CVE-2024-37947 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.7.3 | 2.7.3 | 2024-07-10 | ✓ fixed in latest |
| CVE-2024-37266 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.2 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.2 | < 2.7.2 | 2.7.2 | 2024-06-27 | ✓ fixed in latest |
| CVE-2024-37256 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 2.7.2 | 2.7.2 | 2024-06-27 | ✓ fixed in latest |
| CVE-2024-4902 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 2.7.2 | 2.7.2 | 2024-06-06 | ✓ fixed in latest |
| CVE-2024-5438 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.2 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 2.7.2 | 2.7.2 | 2024-06-06 | ✓ fixed in latest |
| CVE-2024-4279 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.1 | Authorization Bypass Through User-Controlled Key | Medium 6.5 | < 2.7.1 | 2.7.1 | 2024-05-15 | ✓ fixed in latest |
| CVE-2024-4318 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 2.7.1 | 2.7.1 | 2024-05-15 | ✓ fixed in latest |
| CVE-2024-3553 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.0 | Missing Authorization | Medium 6.5 | < 2.7.0 | 2.7.0 | 2024-04-26 | ✓ fixed in latest |
| CVE-2024-3994 | Tutor LMS – eLearning and online course solution [tutor] < 2.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.7.0 | 2.7.0 | 2024-04-24 | ✓ fixed in latest |
| CVE-2024-1503 | Tutor LMS – eLearning and online course solution [tutor] < 2.6.2 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.6.2 | 2.6.2 | 2024-03-12 | ✓ fixed in latest |
| CVE-2024-1502 | Tutor LMS – eLearning and online course solution [tutor] < 2.6.2 | Missing Authorization | Medium 4.3 | < 2.6.2 | 2.6.2 | 2024-03-12 | ✓ fixed in latest |
| CVE-2024-1751 | Tutor LMS – eLearning and online course solution [tutor] < 2.6.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 2.6.2 | 2.6.2 | 2024-03-11 | ✓ fixed in latest |
| CVE-2024-1133 | Tutor LMS – eLearning and online course solution [tutor] < 2.6.1 | Missing Authorization | Medium 4.3 | < 2.6.1 | 2.6.1 | 2024-02-20 | ✓ fixed in latest |
| CVE-2024-1128 | Tutor LMS – eLearning and online course solution [tutor] < 2.6.1 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | Low 3.5 | < 2.6.1 | 2.6.1 | 2024-02-20 | ✓ fixed in latest |
| CVE-2023-49829 | Tutor LMS – eLearning and online course solution [tutor] < 2.3.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 2.3.0 | 2.3.0 | 2023-12-05 | ✓ fixed in latest |
| CVE-2023-4805 | Tutor LMS – eLearning and online course solution [tutor] < 2.3.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.3.0 | 2.3.0 | 2023-09-25 | ✓ fixed in latest |
| CVE-2023-3133 | Tutor LMS – eLearning and online course solution [tutor] < 2.2.1 | Authorization Bypass Through User-Controlled Key | High 7.5 | < 2.2.1 | 2.2.1 | 2023-06-12 | ✓ fixed in latest |
| CVE-2023-25990 | Tutor LMS – eLearning and online course solution [tutor] < 2.2.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.1 | < 2.2.0 | 2.2.0 | 2023-05-30 | ✓ fixed in latest |
| CVE-2023-25700 | Tutor LMS – eLearning and online course solution [tutor] < 2.2.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.2 | < 2.2.0 | 2.2.0 | 2023-05-30 | ✓ fixed in latest |
| CVE-2023-25800 | Tutor LMS – eLearning and online course solution [tutor] < 2.2.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.1 | < 2.2.1 | 2.2.1 | 2023-05-30 | ✓ fixed in latest |
| CVE-2023-25799 | Tutor LMS – eLearning and online course solution [tutor] < 2.1.9 | Missing Authorization | High 8.3 | < 2.1.9 | 2.1.9 | 2023-05-24 | ✓ fixed in latest |
| CVE-2023-0236 | Tutor LMS – eLearning and online course solution [tutor] < 2.0.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.0.10 | 2.0.10 | 2023-01-12 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.13 | — | Unknown | < 1.9.13 | 1.9.13 | 2023-01-10 | ✓ fixed in latest |
| CVE-2022-2563 | Tutor LMS – eLearning and online course solution [tutor] < 2.0.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.0.10 | 2.0.10 | 2022-09-26 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 2.0.9 | — | Unknown | < 2.0.9 | 2.0.9 | 2022-08-22 | ✓ fixed in latest |
| CVE-2021-25017 | Tutor LMS – eLearning and online course solution [tutor] < 1.9.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.9.12 | 1.9.12 | 2021-12-27 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.12 | — | Unknown | < 1.9.12 | 1.9.12 | 2021-12-27 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.12 | — | Unknown | < 1.9.12 | 1.9.12 | 2021-12-27 | ✓ fixed in latest |
| CVE-2021-24873 | Tutor LMS – eLearning and online course solution [tutor] < 1.9.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.9.11 | 1.9.11 | 2021-10-19 | ✓ fixed in latest |
| CVE-2021-24740 | Tutor LMS – eLearning and online course solution [tutor] < 1.9.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 1.9.9 | 1.9.9 | 2021-09-20 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.6 | — | Unknown | < 1.9.6 | 1.9.6 | 2021-08-09 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.6 | — | Unknown | < 1.9.6 | 1.9.6 | 2021-08-09 | ✓ fixed in latest |
| CVE-2021-24455 | Tutor LMS – eLearning and online course solution [tutor] < 1.9.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.9.2 | 1.9.2 | 2021-06-28 | ✓ fixed in latest |
| CVE-2021-24242 | Tutor LMS – eLearning and online course solution [tutor] < 1.8.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Low 3.8 | < 1.8.8 | 1.8.8 | 2021-04-05 | ✓ fixed in latest |
| CVE-2021-24181 | Tutor LMS – eLearning and online course solution [tutor] < 1.7.7 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 1.7.7 | 1.7.7 | 2021-03-15 | ✓ fixed in latest |
| CVE-2021-24183 | Tutor LMS – eLearning and online course solution [tutor] < 1.8.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 1.8.3 | 1.8.3 | 2021-03-15 | ✓ fixed in latest |
| CVE-2021-24184 | Tutor LMS – eLearning and online course solution [tutor] < 1.7.7 | Missing Authorization | High 8.8 | < 1.7.7 | 1.7.7 | 2021-03-15 | ✓ fixed in latest |
| CVE-2021-24185 | Tutor LMS – eLearning and online course solution [tutor] < 1.7.7 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 1.7.7 | 1.7.7 | 2021-03-15 | ✓ fixed in latest |
| CVE-2021-24182 | Tutor LMS – eLearning and online course solution [tutor] < 1.8.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 1.8.3 | 1.8.3 | 2021-03-15 | ✓ fixed in latest |
| CVE-2021-24186 | Tutor LMS – eLearning and online course solution [tutor] < 1.8.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 1.8.3 | 1.8.3 | 2021-03-15 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.7.7 | — | Unknown | < 1.7.7 | 1.7.7 | 2021-03-15 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.8.3 | — | Unknown | < 1.8.3 | 1.8.3 | 2021-03-15 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.7.7 | — | Unknown | < 1.7.7 | 1.7.7 | 2021-03-15 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.13 | — | Unknown | < 1.9.13 | 1.9.13 | 2021-01-10 | ✓ fixed in latest |
| CVE-2020-8615 | Tutor LMS – eLearning and online course solution [tutor] < 1.5.3 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 1.5.3 | 1.5.3 | 2020-02-04 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.5.3 | — | Unknown | < 1.5.3 | 1.5.3 | 2020-02-04 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 3.9.8 | — | Unknown | < 3.9.8 | 3.9.8 | 0000-00-00 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 3.9.8 | — | Unknown | < 3.9.8 | 3.9.8 | 0000-00-00 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 3.9.8 | — | Medium 4.3 | < 3.9.8 | 3.9.8 | 0000-00-00 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 3.9.6 | — | Unknown | < 3.9.6 | 3.9.6 | 0000-00-00 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 3.9.6 | — | Unknown | < 3.9.6 | 3.9.6 | 0000-00-00 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 3.9.5 | — | Unknown | < 3.9.5 | 3.9.5 | 0000-00-00 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 3.9.0 | — | Medium 4.3 | < 3.9.0 | 3.9.0 | 0000-00-00 | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.13 | — | Unknown | < 1.9.13 | 1.9.13 | — | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.12 | — | Unknown | < 1.9.12 | 1.9.12 | — | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.6 | — | Unknown | < 1.9.6 | 1.9.6 | — | ✓ fixed in latest |
| — | Tutor LMS – eLearning and online course solution [tutor] < 1.9.11 | — | Unknown | < 1.9.11 | 1.9.11 | — | ✓ fixed in latest |
| — | Tutor LMS < 1.9.6 - Reflected Cross-Site Scripting | — | Unknown | < 1.9.6 | 1.9.6 | — | ✓ fixed in latest |
| — | Tutor LMS < 1.9.12 - Subscriber+ Stored Cross-Site Scripting | — | Unknown | < 1.9.12 | 1.9.12 | — | ✓ fixed in latest |
| — | Tutor LMS < 1.9.13 - Reflected Cross-Site Scripting | — | Unknown | < 1.9.13 | 1.9.13 | — | ✓ fixed in latest |
| — | Tutor LMS < 2.0.9 - Reflected Cross-Site Scripting | — | Unknown | < 2.0.9 | 2.0.9 | — | ✓ fixed in latest |
| CVE-2024-4223 | Tutor LMS < 2.7.1 - Missing Authorization | — | Unknown | < 2.7.1 | 2.7.1 | — | ✓ fixed in latest |
| CVE-2025-6680 | Tutor LMS < 3.9.0 - Missing Authorization to Sensitive Information Exposure | — | Unknown | < 3.9.0 | 3.9.0 | — | ✓ fixed in latest |
| CVE-2026-0548 | Tutor LMS – eLearning and online course solution < 3.9.5 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion | — | Unknown | < 3.9.5 | 3.9.5 | — | ✓ fixed in latest |
| CVE-2026-1371 | Tutor LMS < 3.9.6 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action | — | Unknown | < 3.9.6 | 3.9.6 | — | ✓ fixed in latest |
| CVE-2026-1375 | Tutor LMS < 3.9.6 - Instructor+ Arbitrary Course Modification and Deletion via IDOR | — | Unknown | < 3.9.6 | 3.9.6 | — | ✓ fixed in latest |
| CVE-2026-3360 | Tutor LMS < 3.9.8 - Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' | — | Unknown | < 3.9.8 | 3.9.8 | — | ✓ fixed in latest |
| CVE-2026-3358 | Tutor LMS < 3.9.8 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment | — | Unknown | < 3.9.8 | 3.9.8 | — | ✓ fixed in latest |
| CVE-2026-3371 | Tutor LMS < 3.9.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification | — | Unknown | < 3.9.8 | 3.9.8 | — | ✓ fixed in latest |
How to fix it
Keep Tutor updated — 4.0.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — 70000+ active installs — 86/100 (597) — max PHP <8.0
- Interactive Content – H5P — 40000+ active installs — 96/100 (61) — max PHP 8.4
- LearnPress – Course Review — 20000+ active installs — 50/100 (8) — max PHP 8.4
- Uncanny Toolkit for LearnDash — 20000+ active installs — 96/100 (105)
- Quiz Maker by AYS — 20000+ active installs — 98/100 (597)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.