SecAlerts
T

Tutor LMS

Security Risk Profile

41
/100
medium

Security Risk Score

Comprehensive risk assessment based on 30 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 16, 2024 to present

30
Total CVEs
11
Critical+High
0
Exploited
10
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
41/100
medium
🆕 6Fresh (<7d)📈 11 in Last 30 Days

Severity Distribution

Critical
2
High
9
Medium
18
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
7
2
XSS
3
3
Infoleak
1

Most Affected Products

1. Tutor LMS WordPress plugin11
2. Themeum Tutor Lms Wordpress10
3. Tutor LMS Tutor LMS7
4. Tutor LMS Tutor LMS Pro5
5. Tutor LMS Tutor LMS – eLearning and online course solution plugin for WordPress2

Recent Vulnerabilities

See more →
CVE-2026-89081
CVSS 6.1medium

Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters

Sep 19, 2026🔧 No Patch
CVE-2026-88944
CVSS 4.3medium

Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter

Sep 19, 2026🔧 No Patch
CVE-2026-89333
CVSS 6.5medium

Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter

Sep 19, 2026🔧 No Patch
CVE-2026-85572
CVSS 4.3medium

Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure

Sep 16, 2026🔧 No Patch
CVE-2026-85569
CVSS 7.2high

Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification

Sep 16, 2026🔧 No Patch
CVE-2026-78175
CVSS 8.8high

Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution

Sep 12, 2026🔧 No Patch
CVE-2026-16759
CVSS 6.5medium

Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters

Aug 28, 2026🔧 No Patch
CVE-2026-19092
CVSS 9.8critical

Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing

Aug 27, 2026🔧 No Patch
CVE-2026-19094
CVSS 5.3medium

Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters

Aug 26, 2026🔧 No Patch
CVE-2026-19093
CVSS 6.8medium

Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path

Aug 22, 2026🔧 No Patch

Monitor Tutor LMS in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Tutor LMS Security Vulnerabilities & Risk Score | 30 CVEs | SecAlerts - SecAlerts