What is CVE-2026-15444?
CVE-2026-15444 is a generic SQL Injection vulnerability in the Tutor LMS plugin for WordPress, affecting versions up to and including 4.0.1. The flaw exists due to insufficient escaping and preparation of the 'coupon_code' parameter, allowing remote attackers to manipulate database queries. Updating to the latest patched version is strongly recommended.
Azərbaycanca: CVE-2026-15444, WordPress üçün Tutor LMS plaginində (4.0.1-ə qədər versiyalarda) aşkar edilmiş generic SQL Injection zəifliyidir. Bu zəiflik 'coupon_code' parametri üzərindən istifadəçi məlumatlarının kifayət qədər təmizlənməməsi səbəbindən yaranır və uzaqdan hücumçuya verilənlər bazasına müdaxilə etməyə imkan verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Tutor LMS plugin for WordPress are affected by CVE-2026-15444?
The vulnerability affects Tutor LMS plugin versions up to and including 4.0.1.
Through which parameter can an attacker exploit the CVE-2026-15444 vulnerability to interfere with the database?
An attacker can perform an SQL Injection attack through the 'coupon_code' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.