CVE-2026-25406: WordPress Tutor LMS Pro plugin <= 3.9.4 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.4.
Other sources
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.8.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25406?
The severity of CVE-2026-25406 is classified as high due to its potential for authentication bypass.
How do I fix CVE-2026-25406?
To fix CVE-2026-25406, update the Tutor LMS Pro plugin to version 3.9.5 or higher.
What does CVE-2026-25406 affect?
CVE-2026-25406 affects the Themeum Tutor LMS Pro plugin versions up to and including 3.9.4.
What is the impact of CVE-2026-25406?
The impact of CVE-2026-25406 allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access.
Is CVE-2026-25406 a common vulnerability?
CVE-2026-25406 represents a common type of security vulnerability found in web applications due to improper authentication checks.