Impact
The vulnerability is an SQL Injection flaw that arises from improper neutralization of special elements within SQL commands in the Tutor LMS plugin. An attacker who can supply data that reaches the affected query could execute arbitrary SQL statements, potentially leaking, modifying, or deleting data stored in the WordPress database. The flaw is a classic input‑validation weakness (CWE‑89) that would compromise the integrity and confidentiality of the site’s data.
Affected Systems
The issue affects Themeum Tutor LMS for WordPress versions from the earliest releases through version 3.7.4 inclusive. Any WordPress installation that currently uses Tutor LMS 3.7.4 or earlier is within the risk envelope.
Risk and Exploitability
With a CVSS score of 7.6 the severity is considered high. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation in the wild at this time, and the vulnerability is not listed in CISA’s KEV catalog. The plugin’s web interface is the probable attack surface, meaning that remote exploitation may be possible from any user who can interact with the plugin’s forms or endpoints without additional authentication requirements.
OpenCVE Enrichment
EUVD