PT-2026-6042 · WordPress · Tutor Lms

Supakiad S

·

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2026-1371

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS versions prior to 3.9.6
Description The Tutor LMS plugin for WordPress has a flaw where sensitive coupon details can be accessed without proper authorization. The issue stems from insufficient validation within the ajax coupon details() function, which only checks for nonces but does not confirm user permissions. This allows users with Subscriber-level access or higher to obtain confidential information about coupons, including coupon codes, discount amounts, usage data, and course/bundle associations.
Recommendations Update Tutor LMS to version 3.9.6 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1371

Affected Products

Tutor Lms