Input validation vulnerability in Tutor LMS – eLearning and online course solution 2.7.0

The Tutor LMS plugin for WordPress is at risk of a security issue called time-based SQL Injection. This happens when the plugin doesn’t properly protect a part of the code called the ‘question_id’ parameter. This vulnerability affects versions up to and including 2.7.0. It allows attackers with special permissions to add their own code to the existing code, which can then be used to get sensitive information from the database.

Detected in:

Tutor LMS – eLearning and online course solution fixed vulnerable versions: >= * <= 2.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.