Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.46% | — | Themeum Tutor LMSAI | 19/9/2026 | 21/9/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.38% | — | Themeum Tutor LMSAI | 19/9/2026 | 21/9/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.46% | — | Themeum Tutor LMSAI | 19/9/2026 | 21/9/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.29% | — | Themeum Tutor LMSAI | 16/9/2026 | 17/9/2026 | The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are not enrolled in, including comments awaiting moderation. | |
| Aplazada | Alta (7.2) | 0.46% | — | Themeum Tutor LMSAI | 16/9/2026 | 17/9/2026 | The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not enforce the permission recorded against an API credential, allowing the holder of a read-only key to act as the administrator account that issued it. | |
| Aplazada | Alta (8.8) | 1.1% | — | Themeum Tutor LMSAI | 12/9/2026 | 15/9/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check,… | |
| Aplazada | Media (6.5) | 0.62% | — | Themeum Tutor LMSAI | 28/8/2026 | 28/8/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. This is due to missing authorization on the handler combined with… | |
| Aplazada | Crítica (9.8) | 2.0% | — | Themeum Tutor LMSAI | 27/8/2026 | 28/8/2026 | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output. | |
| Aplazada | Media (5.3) | 0.21% | — | Themeum Tutor LMSAI | 26/8/2026 | 26/8/2026 | The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a request may load, allowing unauthenticated users to inject SQL and to read question and answer content belonging to courses that are not publicly available. The injected text… | |
| Aplazada | Baja (2.7) | 0.30% | — | Themeum Tutor LMSAI | 22/8/2026 | 26/8/2026 | The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors. | |
| Aplazada | Media (4.3) | 0.27% | — | Themeum Tutor LMSAI | 6/8/2026 | 26/8/2026 | The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses. | |
| Aplazada | Media (5.4) | 0.23% | — | Themeum Tutor LMSAI | 30/7/2026 | 30/7/2026 | The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and… | |
| Aplazada | Media (4.9) | 0.48% | — | Themeum Tutor LMSAI | 28/7/2026 | 28/7/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (4.3) | 0.35% | — | Themeum Tutor LMS Elementor AddonsAI | 21/7/2026 | 22/7/2026 | The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.57% | — | Themeum Tutor LMSAI | 16/7/2026 | 18/7/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (6.5) | 0.34% | — | Themeum Tutor LMSAI | 13/7/2026 | 13/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13. | |
| Aplazada | Alta (7.1) | 0.29% | — | Themeum Tutor LMSAI | 13/7/2026 | 13/7/2026 | The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without… | |
| Aplazada | Media (6.5) | 0.30% | — | Themeum Tutor LMSAI | 13/7/2026 | 13/7/2026 | The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite… | |
| Aplazada | Media (4.3) | 0.28% | — | Themeum Tutor LMSAI | 13/7/2026 | 13/7/2026 | The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML… | |
| Aplazada | Media (5.4) | 0.29% | — | Themeum Tutor LMSAI | 13/7/2026 | 13/7/2026 | The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result. | |
| Aplazada | Media (6.4) | 0.36% | — | Themeum Tutor LMSAI | 1/7/2026 | 1/7/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.3) | 0.28% | — | Tutor LMS PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Themeum Tutor LMSAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions. | |
| Aplazada | Media (5.3) | 0.53% | — | Themeum Tutor LMSAI | 13/5/2026 | 17/6/2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.9.9. This is due to the `get_course_id_by()` function unconditionally trusting the user-supplied `course` GET parameter as the authoritative course ID for… | |
| Aplazada | Media (6.5) | 0.47% | — | Themeum Tutor LMSAI | 17/4/2026 | 17/6/2026 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter combined with direct interpolation into a SQL fragment before being passed to $wpdb->prepare(). This makes it possible for authenticated attackers with… |