CVE-2026-22332: WordPress Tutor LMS Pro plugin <= 3.9.6 - SQL Injection vulnerability
Published Jun 17, 2026
·Updated
Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.
Affected Software
1 affected component
Themeum Tutor LMS Pro<=3.9.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tutor LMS Pro pluginto a version that resolves this vulnerability.Fixed in 3.9.7
Event History
Jun 17, 2026
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-22332?
The severity of CVE-2026-22332 is critical, with a score of 9.3.
2
How do I fix CVE-2026-22332?
To fix CVE-2026-22332, update Tutor LMS Pro plugin to version 3.9.7 or later.
3
What type of vulnerability is described by CVE-2026-22332?
CVE-2026-22332 describes an unauthenticated SQL Injection vulnerability.
4
Which versions of Tutor LMS Pro are affected by CVE-2026-22332?
CVE-2026-22332 affects all versions of Tutor LMS Pro up to and including version 3.9.6.
5
What impact does CVE-2026-22332 have on systems?
CVE-2026-22332 can allow an attacker to execute arbitrary SQL queries, potentially compromising database integrity.