The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.5. This is due to missing authorization checks in the `ajax_coupon_details()` function, which only validates nonces but does not verify user capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive coupon information including coupon codes, discount amounts, usage statistics, and course/bundle applications.
We have discovered 8,566 live websites that are affected by CVE-2026-1371.
| Product | |
| Category | Learning Management System |
| Vulnerable Domains | 8,566 live websites (100% of Tutor LMS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 119 versions ( 100% of all versions) |
| 2,486 websites | |
| 671 websites | |
| 472 websites | |
| 415 websites | |
| 392 websites | |
| 373 websites | |
| 365 websites | |
| 313 websites | |
| 239 websites | |
| 206 websites |
| .com | 4,079 websites |
| .org | 573 websites |
| .pl | 280 websites |
| .com.br | 261 websites |
| .de | 185 websites |
| .net | 177 websites |
| .it | 159 websites |
| .co.uk | 155 websites |
| .fr | 132 websites |
| .nl | 114 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.org | **,*** | ||
| **********.com | **,*** | ||
| ***************.org | **,*** | ||
| *************.org | **,*** | ||
| **********.com | **,*** | ||
| ********************.com | ***,*** | ||
| *****.com | ***,*** | ||
| ************.org | ***,*** | ||
| *****.co | ***,*** | ||
| *****************.org | ***,*** |
FAQ