CVE-2025-58993: WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS tutor allows SQL Injection.This issue affects Tutor LMS: from n/a through <= 3.7.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58993?
CVE-2025-58993 is a high-severity vulnerability due to its potential for SQL Injection attacks.
How do I fix CVE-2025-58993?
To fix CVE-2025-58993, update Themeum Tutor LMS to the latest version that addresses this vulnerability.
What products are affected by CVE-2025-58993?
CVE-2025-58993 affects Themeum Tutor LMS versions up to and including 3.7.4.
What type of vulnerability is CVE-2025-58993?
CVE-2025-58993 is classified as an SQL Injection vulnerability.
Can CVE-2025-58993 be exploited remotely?
Yes, CVE-2025-58993 can be exploited remotely if attackers can interact with the affected software.