Skip to main content

Software intelligence

Tutor vulnerabilities

80 tracked advisories · slug tutor

Important: Tutor appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

80

Latest advisory

27 August 2026

CISA KEV matches

0

In this WordPress feed

WordPress slug

tutor

Plugin

What this means for Tutor

This catalog lists 80 known advisories affecting Tutor. The most recent was published on 27 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters

    May allow attackers to run arbitrary code on the server if exploited.

    Published 27 August 2026

  • Tutor LMS – eLearning and online course solution < 4.0.0 - Missing Authorization

    This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.

    Published 30 July 2026

  • Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter

    May allow attackers to read or modify database contents beyond intended access.

    Published 27 July 2026

Vulnerability types

  • SQL injection19
  • Cross-site scripting16
  • CSRF4
  • Remote code execution1
  • Directory traversal1
  • Privilege escalation1

Authentication (inferred from titles)

  • Unauthenticated8
  • Authenticated43
  • Unspecified29

Advisory history

Known Tutor advisories published by month.

All advisories

4660 of 80

4 / 6

Check whether your installed version is affected

SiteRespond Defence matches your installed Tutor version against this catalog when the Defence plugin is connected to your WordPress site.