/Vulnerability Library

Tutor LMS <= 2.1.10 - SQL Injection

CVE-2024-1751
Verified

Description

Tutor LMS – eLearning and online course solution plugin for WordPress [all versions up to 2.6.1] contains a time-based SQL Injection caused by insufficient escaping on the question_id parameter in SQL queries, letting authenticated attackers with subscriber or higher access extract sensitive information, exploit requires attacker to be authenticated with subscriber or higher privileges.

Severity

High

CVSS Score

7.5

Exploit Probability

3%

Published Date

February 4, 2026

Template Author

shivam kamboj

CVE-2024-1751.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2024-1751
CWE ID:
cwe-89

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor/tutor-lms-2110-unauthenticated-sql-injectionhttps://plugins.trac.wordpress.org/changeset?old=2919134%40tutor&new=2919134%40tutorhttps://nvd.nist.gov/vuln/detail/CVE-2024-1751

Remediation Steps

Update to version 2.6.2 or later to fix the vulnerability.