CVE-2026-3371 - Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification
CVE ID :CVE-2026-3371
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Related Vulnerabilities
- CVE-2026-33704: Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including stu HIGH
- CVE-2026-33141: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Referenc MEDIUM
- CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects HIGH
- CVE-2026-5507: When restoring a session from cache, a pointer from the serialized session data is used in a free op MEDIUM
- CVE-2026-6067: A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds HIGH
Related Coverage
Threat Actors