CVE-2026-3371 - Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification
CVE ID :CVE-2026-3371
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Related Vulnerabilities
- CVE-2026-22560: An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected MEDIUM
- CVE-2021-47961: A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows HIGH
- CVE-2026-4162: The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and HIGH
- CVE-2026-5412: In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. CRITICAL
- CVE-2026-6068: NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling MEDIUM
Related Coverage
Threat Actors