Executive brief
Tutor LMS Pro is a popular WordPress plugin used to create and manage online courses and learning management systems. A critical security flaw allows unauthenticated attackers to interact directly with the website's database without needing a login. This could lead to the theft of sensitive student and instructor information, or disruption of the learning platform's operations.
Technical details
A SQL injection vulnerability exists in the Tutor LMS Pro plugin for WordPress due to improper neutralization of special elements used in an SQL command (CWE-89). The flaw is accessible to unauthenticated remote attackers, meaning no valid user account or special privileges are required to trigger the exploit. By sending specially crafted requests to the affected site, an attacker can execute arbitrary SQL queries against the backend database. This can result in the unauthorized extraction of sensitive data, such as user credentials and personal information, or limited impact on database availability. The issue is resolved in version 3.9.7.
Affected products
- Themeum Tutor LMS Pro <= 3.9.6
Timeline
- 2025-09-27: other: Reported by researcher 0xd4rk5id3
- 2026-01-13: advisory: Initial Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD
- 2026-01-13: patched: Patch released in version 3.9.7