Reflected Cross-Site Scripting Vulnerability in Tutor LMS for WordPress
CVE-2026-89081
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-89081?
The Tutor LMS plugin for WordPress is susceptible to a reflected cross-site scripting issue through the 'search' parameter. This vulnerability exists in all versions up to and including 4.0.8 due to inadequate input validation and output encoding practices. An attacker could exploit this flaw to inject arbitrary web scripts into web pages viewed by users, potentially leading to malicious actions when users interact with certain links. This poses a risk particularly for environments where users can be manipulated into clicking deceptive links.
Affected Version(s)
Tutor LMS β eLearning and online course solution 0 <= 4.0.8