CVE-2026-3371 - Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification
CVE ID :CVE-2026-3371
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Related Vulnerabilities
- CVE-2026-33141: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Referenc MEDIUM
- CVE-2026-35660: OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent HIGH
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
- CVE-2026-4156: ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. HIGH
- CVE-2026-23780: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in HIGH
Related Coverage
Threat Actors