CVE-2026-15022

Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The payload is stored at quiz-attempt time via the wp_ajax_tutor_quiz_abandon handler, but the injected SQL executes only when a privileged user or Tutor REST API key holder requests the /wp-json/tutor/v1/quiz-attempt-details/{id} endpoint, making this a second-order (stored) injection chain.


We have discovered 8,875 live websites that are affected by CVE-2026-15022.

Run a Free Instant Scan




Affected Software

Product  Tutor LMS
Category Learning Management System
Vulnerable Domains8,875 live websites (100% of Tutor LMS install base)
Vulnerable Versions
  • from 0 through 4
Vulnerable Versions Count127 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 16, 2026
  • Updated - Jul 18, 2026

Credits

  • Supakiad S. (m3ez) (finder)

Website Distribution by Country

Number of websites using CVE-2026-15022
United States2,534 websites



Germany683 websites
Cyprus439 websites
Poland438 websites
France435 websites
India404 websites
GB393 websites
Brazil327 websites
Spain258 websites
Italy238 websites

Website Distribution by TLD

Number of websites using CVE-2026-15022
.com4,120 websites
.org597 websites
.pl347 websites
.com.br289 websites
.de209 websites
.net180 websites
.it167 websites
.fr153 websites
.co.uk146 websites
.nl121 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15022

Top websites that are affected by CVE-2026-15022. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org United States**,***
**********.com United States**,***
*****************.com GB**,***
***************.org United States**,***
*************.org United States**,***
**********.com GB**,***
********************.com United States***,***
*****.com France***,***
**************.com Spain***,***
************.org United States***,***
See full domain list

FAQ

CVE-2026-15022 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Tutor LMS
A total of 8,875 websites have been identified as vulnerable to CVE-2026-15022, based on global website indexing conducted by WebTechSurvey.
The Tutor LMS is affected by the CVE-2026-15022 vulnerability.
Tutor LMS versions up to and including 4 are vulnerable to CVE-2026-15022.

References