Reflected Cross-Site Scripting Vulnerability in Tutor LMS for WordPress
CVE-2026-89081

6.1MEDIUM

What is CVE-2026-89081?

The Tutor LMS plugin for WordPress is susceptible to a reflected cross-site scripting issue through the 'search' parameter. This vulnerability exists in all versions up to and including 4.0.8 due to inadequate input validation and output encoding practices. An attacker could exploit this flaw to inject arbitrary web scripts into web pages viewed by users, potentially leading to malicious actions when users interact with certain links. This poses a risk particularly for environments where users can be manipulated into clicking deceptive links.

Affected Version(s)

Tutor LMS – eLearning and online course solution 0 <= 4.0.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Filip Kowalski (Agentunio)
.