PT-2026-81952 · WordPress · Tutor Lms

·

CVE-2026-19094

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS versions prior to 4.0.6
Description The software fails to validate values used in database queries and does not restrict the template files that a request can load. This allows unauthenticated users to perform SQL injection, where injected text is interpreted as grammar rather than data. This issue enables the unauthorized reading of question and answer content from courses that are not publicly available. The vulnerability is triggered via the offset and item per page parameters.
Recommendations Update Tutor LMS to version 4.0.6 or later. Avoid using the offset and item per page parameters until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19094

Affected Products

Tutor Lms