Tutor LMS – eLearning and online course solution

Vulnerabilities 79Slug tutorLatest version 3.9.10WordPress.org →

Minimum safe version

3.9.9

Update to 3.9.9 or later to address 79 fixable vulnerabilities

Latest available3.9.10
N/A
2026-04-20< 3.9.8

Tutor LMS – eLearning and online course solution <= 3.9.7 - Missing Authorization

Medium 4.3
2025-10-25< 3.9.0

Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure

N/A
2026-01-20< 3.9.5

Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion

N/A
2026-02-02< 3.9.6

Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action

N/A
2026-02-02< 3.9.6

Tutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion

Medium 4.3
2026-04-11< 3.9.8

Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification

N/A
2026-04-10< 3.9.8

Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment

N/A
2026-04-09< 3.9.8

Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter

N/A
< 1.9.11

Tutor LMS &lt; 2.0.9 - Reflected Cross-Site Scripting

N/A
2023-01-10< 1.9.13

WordPress Tutor LMS Plugin <= 1.9.12 is vulnerable to Cross Site Scripting (XSS)

N/A
< 1.9.6

Tutor LMS &lt; 1.9.6 - Reflected Cross-Site Scripting

N/A
< 1.9.12

Tutor LMS &lt; 1.9.12 - Subscriber+ Stored Cross-Site Scripting

N/A
< 1.9.13

Tutor LMS &lt; 1.9.13 - Reflected Cross-Site Scripting

N/A
2021-01-10< 1.9.13

Tutor LMS <= 1.9.12 - Reflected Cross-Site Scripting

N/A
2021-08-09< 1.9.6

Tutor LMS <= 1.9.5 - Cross-Site Scripting

N/A
2021-12-27< 1.9.12

Tutor LMS <= 1.9.11 - Stored Cross-Site Scripting

N/A
2022-08-22< 2.0.9

Tutor LMS – eLearning and online course solution 2.0.0-2.0.8 - Reflected Cross-Site Scripting

N/A
2020-02-04< 1.5.3

WordPress Tutor LMS plugin <= 1.5.2 - Cross-Site Request Forgery (CSRF) vulnerability

N/A
2021-03-15< 1.7.7

WordPress Tutor LMS plugin <= 1.7.6 - Unprotected AJAX Action to Privilege Escalation vulnerability

N/A
2021-03-15< 1.8.3

WordPress Tutor LMS plugin <= 1.8.2 - Multiple Union SQL Injection (SQLi) vulnerabilities

N/A
2021-03-15< 1.7.7

WordPress Tutor LMS plugin <= 1.7.6 - Multiple Blind/Time-based SQL Injection (SQLi) vulnerabilities

N/A
2021-08-09< 1.9.6

WordPress Tutor LMS plugin <= 1.9.5 - Reflected Cross-Site Scripting (XSS) vulnerability

N/A
2021-12-27< 1.9.12

WordPress Tutor LMS plugin <= 1.9.11 - Stored Cross-Site Scripting (XSS) vulnerability