Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4.
Metrics
Affected Vendors & Products
Fixes
Solution
Update the WordPress Tutor LMS plugin to the latest available version (at least 3.8.0).
Workaround
No workaround given by the vendor.
References
History
Tue, 09 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Themeum
Themeum tutor Lms Wordpress Wordpress wordpress |
|
Vendors & Products |
Themeum
Themeum tutor Lms Wordpress Wordpress wordpress |
Tue, 09 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4. | |
Title | WordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection Vulnerability | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-09T18:29:05.885Z
Reserved: 2025-09-06T04:45:29.149Z
Link: CVE-2025-58993

No data.

Status : Received
Published: 2025-09-09T17:16:14.233
Modified: 2025-09-09T17:16:14.233
Link: CVE-2025-58993

No data.

Updated: 2025-09-09T21:31:19Z