CVE-2026-3371 - Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification
CVE ID :CVE-2026-3371
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Related Vulnerabilities
- CVE-2026-40217: LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting HIGH
- CVE-2026-31939: Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exe HIGH
- CVE-2026-40242: Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint HIGH
- CVE-2026-40156: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file name HIGH
- CVE-2026-32894: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
Related Coverage
Threat Actors