Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.41% | — | Themeum Tutor LMSAI | 17/4/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_course_content_order() function. The function only validates the nonce (CSRF… | |
| Aplazada | Media (5.4) | 0.29% | — | Themeum Tutor LMSAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7. | |
| Aplazada | Media (4.3) | 0.34% | — | Themeum Tutor LMSAI | 11/4/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authorization checks in the `save_course_content_order()` private method, which is called unconditionally by the… | |
| Aplazada | Media (5.4) | 0.39% | — | Themeum Tutor LMSAI | 11/4/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, 3.9.7. This is due to missing post_status validation in the `enroll_now()` and `course_enrollment()` functions. Both enrollment endpoints verify the… | |
| Aplazada | Alta (7.5) | 0.62% | — | Themeum Tutor LMSAI | 10/4/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authentication and authorization checks in the `pay_incomplete_order()` function. The function accepts an… | |
| Aplazada | Alta (8.1) | 0.34% | — | Themeum Tutor LMS PROAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.4. | |
| Aplazada | Media (6.5) | 0.29% | — | Themeum Tutor LMSAI | 19/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4. | |
| Aplazada | Crítica (9.8) | 0.66% | — | Themeum Tutor LMS PROAI | 10/3/2026 | 17/6/2026 | The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. This is due to the plugin failing to verify that the email provided in the authentication request matches the email from the validated OAuth token. This makes it… | |
| Aplazada | Media (6.5) | 0.34% | — | Themeum Tutor LMSAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.5. | |
| Aplazada | Alta (7.5) | 0.49% | 💥 PoC | Themeum Tutor LMSAI | 28/2/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (8.1) | 0.39% | 💥 PoC | Themeum Tutor LMSAI | 3/2/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3.9.5. This is due to missing object-level authorization checks in the `course_list_bulk_action()`, `bulk_delete_course()`, and… | |
| Aplazada | Media (5.3) | 0.33% | — | Themeum Tutor LMSAI | 3/2/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.5. This is due to missing authorization checks in the `ajax_coupon_details()` function, which only validates nonces but does not verify user capabilities.… | |
| Aplazada | Media (5.9) | 0.24% | — | Themeum Tutor LMS Bunnynet IntegrationAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS BunnyNet Integration tutor-lms-bunnynet-integration allows DOM-Based XSS.This issue affects Tutor LMS BunnyNet Integration: from n/a through <= 1.0.0. | |
| Aplazada | Baja (3.8) | 0.33% | — | Themeum Tutor LMSAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4. | |
| Aplazada | Media (4.3) | 0.22% | — | Themeum Tutor LMSAI | 9/1/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.22% | — | Themeum Tutor LMSAI | 9/1/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.22% | — | Themeum Tutor LMSAI | 9/1/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.24% | — | Themeum Tutor LMSAI | 8/1/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.26% | — | Themeum Tutor LMS Elementor AddonsAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons allows Stored XSS.This issue affects Tutor LMS Elementor Addons: from n/a through <= 3.0.1. | |
| Analizada | Media (4.3) | 0.22% | — | Themeum Tutor LMS | 25/10/2025 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3. This makes it possible for authenticated attackers, with tutor-level access and above, to view assignments for courses they don't teach which may… | |
| Aplazada | Media (5.4) | 0.18% | — | Tutorwms Tutor LMS PROAI | 25/10/2025 | 17/6/2026 | The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.3 due to missing validation on a user controlled key when viewing and editing assignments through the tutor_assignment_submit() function. This makes… | |
| Analizada | Media (5.3) | 0.29% | — | Themeum Tutor LMS | 25/10/2025 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check while verifying webhook signatures on the "verifyAndCreateOrderData" function in all versions up to, and including, 3.8.3. This makes it possible for… | |
| Aplazada | Alta (7.6) | 0.28% | — | Themeum Tutor LMSAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS tutor allows SQL Injection.This issue affects Tutor LMS: from n/a through <= 3.7.4. | |
| Aplazada | Media (4.3) | 0.11% | — | Sertifier Certificate AND Badge Maker FOR Wordpress Tutor LMSAI | 23/8/2025 | 17/6/2026 | The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19. This is due to missing or incorrect nonce validation on the 'sertifier_settings' page. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (8.8) | 0.36% | — | Tutorlms Tutor LMS PROAI | 13/8/2025 | 17/6/2026 | The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in the get_submitted_assignments() function in all versions up to, and including, 3.7.0 due to insufficient escaping on the user supplied parameter and lack of… |