Junglewise Threat Intelligence

CVE-2026-89081: Tutor LMS reflected cross-site scripting in search parameter

CVE-2026-89081 · Severity: medium · CVSS 6.1 · Published 2026-09-19

Technologies: Themeum Tutor LMS. Vendors: Themeum.

Executive brief

Tutor LMS is a WordPress plugin that provides online course management and eLearning functionality. The plugin fails to properly sanitize user input in its search feature, allowing attackers to inject malicious scripts that execute in users' browsers. An attacker can trick a user into clicking a crafted link to steal session data, deface content, or perform unauthorized actions on behalf of the victim.

Technical details

The plugin is vulnerable to reflected cross-site scripting (XSS) via insufficient input sanitization and output escaping of the 'search' parameter. The vulnerability affects all versions up to and including 4.0.8 and can be exploited by unauthenticated attackers through user interaction (link-click). An attacker gains the ability to execute arbitrary JavaScript in the context of an authenticated user's session.

Affected products

  • Themeum Tutor LMS up to and including 4.0.8

Timeline

  • 2026-09-19: disclosed

References

Related threats