CVE-2026-6080Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter combined with direct interpolation into a SQL fragment before being passed to $wpdb->prepare(). This makes it possible for authenticated attackers with Admin-level access and above to append additional SQL queries and extract sensitive information from the database.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-17: 3PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-17: 204-17
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6080-tutor-version-3-9-8-medium-vulnerability-proof-of-concept CVE-2026-6080 #WordPress plugin #vulnerability tutor #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A link to a proof‑of‑concept for CVE‑2026‑6080 affecting Tutor plugin 3.9.8 is provided, with no indications of active exploitation, a patch, or detailed technical data.

    0000042
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6080 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter co… https://www.cve.org/CVERecord?id=CVE-2026-6080

    Post summary

    The post announces a SQL injection flaw in the Tutor LMS WordPress plugin affecting versions up to 3.9.8.

    0000068
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6080 SQL Injection in Tutor LMS Plugin for WordPress Versions Up to 3.9.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6080

    Post summary

    The text reports a CVE for SQL injection in Tutor LMS Plugin up to v3.9.8, but lacks PoC, exploit code, active exploitation, or patch information.

    0000042
    4.0K followersView on X

Explore more