CVE-2026-19094

Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters

The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a request may load, allowing unauthenticated users to inject SQL and to read question and answer content belonging to courses that are not publicly available. The injected text reaches the query as grammar rather than as data, and on the database engines tested it does not yield extraction of arbitrary data, so the confidentiality impact is the disclosed course content rather than the database at large.


We have discovered 1,739 live websites that are affected by CVE-2026-19094.

Run a Free Instant Scan




Affected Software

Product  Tutor LMS
Category Learning Management System
Vulnerable Domains1,739 live websites (20% of Tutor LMS install base)
Vulnerable Versions
  • from 4 through 4.0.6
Vulnerable Versions Count5 versions ( 3.79% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 26, 2026
  • Updated - Aug 26, 2026

Credits

  • Jakub Herman (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-19094
United States664 websites



Germany164 websites
GB91 websites
France84 websites
Cyprus82 websites
India60 websites
Poland57 websites
Brazil43 websites
Canada42 websites
Italy40 websites

Website Distribution by TLD

Number of websites using CVE-2026-19094
.com912 websites
.org157 websites
.de65 websites
.pl49 websites
.net34 websites
.com.br33 websites
.co.uk32 websites
.it31 websites
.fr27 websites
.nl26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-19094

Top websites that are affected by CVE-2026-19094. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org United States**,***
*************.org United States**,***
************.org United States***,***
*****************.org United States***,***
****.nl Netherlands***,***
****************.com United States***,***
******.be Belgium***,***
***********.in India***,***
*******************.com United States***,***
**************.com United States***,***
See full domain list

FAQ

CVE-2026-19094 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Tutor LMS
A total of 1,739 websites have been identified as vulnerable to CVE-2026-19094, based on global website indexing conducted by WebTechSurvey.
The Tutor LMS is affected by the CVE-2026-19094 vulnerability.
Tutor LMS versions up to 4.0.6 are vulnerable to CVE-2026-19094.
CVE-2026-19094 is resolved in version 4.0.6 of Tutor LMS.