As part of our ongoing commitment to making the internet safer, Ikzero actively participates in responsible vulnerability disclosure programs. In early 2024, our Principal Consultant, Muhammad Hassham Nagori, discovered a critical SQL injection vulnerability in the popular Tutor LMS WordPress plugin, used by over 80,000 websites worldwide.
CVE-2024-1751 is a CVSS 8.8 authenticated SQL injection in Tutor LMS versions up to 2.6.1, a WordPress LMS plugin used by over 80,000 websites, responsibly disclosed through the Wordfence Bug Bounty Program and patched in version 2.6.2 on March 11, 2024.
Vulnerability Summary
Plugin Tutor LMS by Themeum
Vulnerability Authenticated SQL Injection (Time-Based)
CVE CVE-2024-1751
Affected Versions Up to and including 2.6.1
Patched Version 2.6.2 (March 11, 2024)
Severity High (CVSS 8.8)
Reported Via Wordfence Bug Bounty Program
Discovered By Muhammad Hassham Nagori (Principal Consultant, Ikzero)
Technical Analysis
During a routine security research engagement, our Principal Consultant identified that the question_id parameter within Tutor LMS quiz functionality was not properly sanitized before being incorporated into SQL queries. This created a time-based blind SQL injection vector exploitable by any authenticated user, including those with basic subscriber or student-level access.
An attacker exploiting this flaw could extract sensitive information directly from the WordPress database, including administrator credentials, user personal data, and payment information.
Impact Assessment
-
Student data exposure: Names, emails, payment details, and course progress at risk
-
Credential theft: Admin password hashes could be extracted and cracked offline
-
Full site takeover: Compromised admin credentials lead to complete WordPress control
-
Regulatory implications: GDPR and data privacy violations for affected institutions
Responsible Disclosure Timeline
-
Discovery: Vulnerability identified by our Principal Consultant during independent security research
-
Disclosure: Responsibly reported through the Wordfence Bug Bounty Program
-
Vendor Response: Themeum acknowledged and began developing a fix
-
Patch Released: Version 2.6.2 released on March 11, 2024
-
Firewall Protection: Wordfence deployed WAF rules to protect users before the patch was widely adopted
Lessons for Website Owners
-
Update plugins immediately: Delayed updates leave you exposed to known vulnerabilities
-
Deploy a Web Application Firewall: Virtual patching protects you while vendors develop fixes
-
Audit your plugin stack: Every plugin is an additional attack surface
-
Invest in manual security testing: Automated scanners would not have found this vulnerability
-
Apply least privilege: This vulnerability required only subscriber-level access
Why This Matters for Your Business
When you work with Ikzero, you are working with a team that actively discovers zero-day vulnerabilities in production software. Our Principal Consultant applies this same deep, manual analysis methodology to every penetration test and security assessment we deliver.
Is Your Web Application Secure?
Vulnerabilities like this could be lurking in your stack right now. Schedule a free security consultation with our team today.
Reference: Wordfence Advisory: SQL Injection Vulnerability Patched in Tutor LMS



