S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 9, 2026

CVE-2024-1751 Scanner

CVE-2024-1751 Scanner - SQL Injection vulnerability in Tutor LMS

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-1751
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber/student access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Tutor LMS – eLearning and online course solutionby themeum
0
tutor_lmsby themeum
0
Updated Aug 22, 2026View on NVD →
Detail

Tutor LMS is a widely-used eLearning and online course solution plugin for WordPress, frequently employed by educational institutions and content creators to offer online courses. It supports the creation and management of courses, quizzes, and learning materials, providing users with a comprehensive educational platform. The plugin is popular due to its user-friendly interface and powerful customization features. Entities including educational institutions, training centers, and individual instructors utilize Tutor LMS to facilitate online learning experiences. Its usage spans across various educational domains, making it integral to digital learning systems. By providing a robust platform for eLearning, Tutor LMS enhances the reach and effectiveness of online education.

SQL Injection is a critical web security vulnerability that allows attackers to interfere with queries that an application makes to its database. It typically allows an attacker to view data that they are not normally able to retrieve, like other users' data, or otherwise unauthorized parts of the database. In the context of Tutor LMS, this vulnerability is present due to improper escaping of SQL queries, particularly involving the 'question_id' parameter. It can be exploited by users with subscriber or higher privileges, allowing them to access sensitive information. This type of vulnerability can lead to severe data exposure and potential breaches within the application. Addressing SQL Injection vulnerabilities is crucial to maintaining the confidentiality, integrity, and availability of database systems.

The SQL injection vulnerability in Tutor LMS is caused by inadequate input sanitization on the 'question_id' parameter, which is included in SQL queries. Attackers with appropriate privileges can exploit this by inserting malicious SQL commands into this parameter, enabling unauthorized retrieval of data from the database. Furthermore, the vulnerability is time-based, allowing detection through abnormal query execution times. It primarily affects the administrative AJAX operations, which are essential for managing course content. Due to the nature of the WordPress CMS and its plugins, such vulnerabilities can have far-reaching impacts if not addressed promptly. The authenticated nature of this exploit requires attackers to have prior access to a user account with specific privileges.

If successfully exploited, the SQL injection vulnerability in Tutor LMS can lead to unauthorized access and retrieval of sensitive information from the database. This includes, but is not limited to, confidential user information, including personal data and potentially financial details depending on the installation's setup. The breach could result in data leakage, reputation damage, regulatory fines, and loss of customer trust. Additionally, exploiting such vulnerabilities can serve as a foothold for further attacks, allowing malicious entities to escalate privileges or inject additional commands to compromise the entire application or underlying infrastructure. Swift remedial action is essential to prevent these damaging outcomes.

REFERENCES

Solution Advice
  • Update to Tutor LMS version 2.6.2 or later to address the SQL Injection vulnerability.
  • Ensure regular updates for all plugins to protect against known vulnerabilities.
  • Implement input validation and proper escaping of SQL queries within applications.
  • Limit user permissions according to the principle of least privilege to minimize potential exploitation impacts.
  • Consider employing a web application firewall (WAF) to block malicious SQL statements.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.