Description
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-09-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

This vulnerability, identified as a Reflected Cross‑Site Scripting flaw, allows an unauthenticated attacker to inject arbitrary scripts via the 'search' and 'back_url' parameters. Because the plugin fails to properly sanitise or escape these inputs, a malicious URL can be crafted that, when clicked by a victim, causes the browser to execute injected JavaScript. The resulting impact is credential theft or a session hijack in the victim's context, compromising confidentiality and integrity on the affected site.

Affected Systems

The issue covers the Tutor LMS eLearning plugin for WordPress versions up to and including 4.0.8. The plugin is developed and distributed by themeum. Clients running Tutor LMS 4.0.8 or earlier are therefore exposed.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, and the EPSS score is not reported. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation reports yet. However, because the attack requires only a crafted link and does not need authentication, attackers can embed the payload in emails or social media posts to persuade users to click. Consequently, the potential for damage remains high until the plugin is upgraded.

Generated by OpenCVE AI on September 19, 2026 at 10:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Tutor LMS plugin to version 4.0.9 or later, which includes proper sanitisation for the vulnerable parameters.
  • If an upgrade cannot be applied immediately, configure a Web Application Firewall to detect and block malicious input containing the 'search' and 'back_url' parameters, or to automatically escape JavaScript payloads.
  • As a temporary workaround, restrict access to URLs that use the 'search' and 'back_url' parameters to authenticated users only so that the plugin’s internal navigation must be used instead of direct links.

Generated by OpenCVE AI on September 19, 2026 at 10:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum tutor Lms – Elearning And Online Course Solution
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum tutor Lms – Elearning And Online Course Solution
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Themeum Tutor Lms – Elearning And Online Course Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:26.171Z

Reserved: 2026-09-10T19:43:42.347Z

Link: CVE-2026-89081

cve-icon Vulnrichment

Updated: 2026-09-19T13:56:51.011Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:16.303

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-89081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')