Medium 5.4
2025-10-25< 3.9.0
Tutor LMS Pro – eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments
Minimum safe version
3.9.9
Update to 3.9.9 or later to address 9 fixable vulnerabilities
Tutor LMS Pro – eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments
Tutor LMS Pro <= 3.9.6 - Unauthenticated SQL Injection
Tutor LMS Pro <= 3.9.5 - Authentication Bypass via Social Login
CVE-2026-25406
WordPress Tutor LMS Pro Plugin <= 3.7.0 is vulnerable to SQL Injection
CVE-2024-5784
CVE-2024-4223
CVE-2024-4222
CVE-2024-4352
CVE-2024-4351