CVE-2026-3371 - Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification
CVE ID :CVE-2026-3371
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Related Vulnerabilities
- CVE-2026-35641: OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hoo HIGH
- CVE-2026-40162: Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability wa HIGH
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-40163: Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, HIGH
Related Coverage
Threat Actors