SQL Injection Vulnerability in Tutor LMS Plugin for WordPress
CVE-2026-6080
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 April 2026
What is CVE-2026-6080?
The Tutor LMS plugin for WordPress has a SQL Injection vulnerability, allowing authenticated users with Admin-level access to exploit insufficient escaping on the 'date' parameter. This flaw occurs when the plugin interpolates this parameter directly into a SQL fragment, which is then executed without proper sanitization via $wpdb->prepare(). As a result, attackers can append additional SQL queries, posing a risk of unauthorized access to sensitive database information.
Affected Version(s)
Tutor LMS β eLearning and online course solution 0 <= 3.9.8