PT-2026-81952 · WordPress · Tutor Lms
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tutor LMS versions prior to 4.0.6
Description
The software fails to validate values used in database queries and does not restrict the template files that a request can load. This allows unauthenticated users to perform SQL injection, where injected text is interpreted as grammar rather than data. This issue enables the unauthorized reading of question and answer content from courses that are not publicly available. The vulnerability is triggered via the
offset and item per page parameters.Recommendations
Update Tutor LMS to version 4.0.6 or later.
Avoid using the
offset and item per page parameters until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tutor Lms