CVE-2024-1751: high-severity vulnerability in themeum Tutor LMS – eLearning and online…
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
Published · Updated
36Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.8epss 3.1%
exploitation probability
3.1%top 13% of all CVEs
observed exploitation
nono source reports it
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber/student access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
themeum · Tutor LMS – eLearning and online course solutionRelated CVEs — themeum Tutor LMS – eLearning and online…
In the same product, most dangerous first.
CVE-2024-10400HIGHTutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filterEPSS 83.1%CVE-2026-78175HIGHTutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code ExecutionEPSS 1.1%CVE-2026-3360HIGHTutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' ParameterEPSS 0.6%CVE-2026-16759MEDIUMTutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST ParametersEPSS 0.6%CVE-2024-10393MEDIUMTutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User RegistrationEPSS 0.6%CVE-2026-15022MEDIUMTutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer ArrayEPSS 0.6%
References
https://plugins.trac.wordpress.org/browser/tutor/tags/2.6.1/classes/Utils.php#L4555https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3049105%40tutor&new=3049105%40tutor&sfp_email=&sfph_mail=https://www.wordfence.com/threat-intel/vulnerabilities/id/f9cee379-79f8-4a60-b1bb-ccab1e954512?source=cve