CVE-2026-42698: WordPress Tutor LMS plugin <= 4.1.1 - Race Condition vulnerability
Published Oct 8, 2026
·Updated
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leveraging Race Conditions.This issue affects Tutor LMS: from n/a through 4.1.1.
Affected Software
1 affected component
Themeum Tutor LMS<=4.1.1
Event History
Oct 8, 2026
CVE Published
via MITRE·01:14 PM
Data Sourced
via MITRE·01:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges. It can be exploited over the network without user interaction, but the attacker must be able to issue concurrent requests that trigger the affected shared-resource handling.
2
What is the likely security impact?
The recorded impact is integrity-only: successful exploitation may allow unauthorized modification of affected data or state. No confidentiality or availability impact is listed.
3
Is Tutor LMS 4.1.1 affected?
Yes. The affected range includes Tutor LMS through version 4.1.1. The available data does not identify a fixed version.