๐Ÿ” CVE Alert

CVE-2026-25406

HIGH 8.8

WordPress Tutor LMS Pro plugin <= 3.9.4 - Broken Authentication vulnerability

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
6th

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.4.

CWE CWE-288
Vendor themeum
Product tutor lms pro
Published Mar 25, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for themeum tutor lms pro

Be the first to know when new high vulnerabilities affecting themeum tutor lms pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Themeum / Tutor LMS Pro
n/a โ‰ค <= 3.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/tutor-pro/vulnerability/wordpress-tutor-lms-pro-plugin-3-9-4-broken-authentication-vulnerability?_s_id=cve

Credits

Phat RiO | Patchstack Bug Bounty Program