<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Themeum CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/themeum/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/themeum.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical Themeum vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 12 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-78175 · CVSS 8.8</title>
      <link>https://cvebrief.com/cve/cve-2026-78175/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-78175</guid>
      <pubDate>Sat, 12 Sep 2026 12:00:00 GMT</pubDate>
      <description>The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-19092 · CVSS 9.8 · Tutor LMS</title>
      <link>https://cvebrief.com/cve/cve-2026-19092/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-19092</guid>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>The Tutor LMS WordPress plugin before 4.0.6 is vulnerable to an injection flaw allowing unauthenticated users to execute arbitrary zero-argument PHP functions and capture the resulting output. Fix documented: 4.0.6 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-12275 · CVSS 7.1 · Tutor LMS</title>
      <link>https://cvebrief.com/cve/cve-2026-12275/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-12275</guid>
      <pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate>
      <description>The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enro Fix documented: 3.9.13 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-57724 · CVSS 9.8 · Kirki</title>
      <link>https://cvebrief.com/cve/cve-2026-57724/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-57724</guid>
      <pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
      <description>A deserialization of untrusted data vulnerability in the Themeum Kirki WordPress plugin allows for PHP object injection. Fix documented: 6.0.13 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-57726 · CVSS 9.3 · Kirki</title>
      <link>https://cvebrief.com/cve/cve-2026-57726/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-57726</guid>
      <pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
      <description>Themeum Kirki is susceptible to a Blind SQL Injection vulnerability, allowing unauthenticated attackers to manipulate SQL queries. Fix documented: 6.0.13 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-57727 · CVSS 7.5 · Kirki</title>
      <link>https://cvebrief.com/cve/cve-2026-57727/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-57727</guid>
      <pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
      <description>Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels Fix documented: 6.2.1 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-8206 · CVSS 9.8 · Kirki Plugin</title>
      <link>https://cvebrief.com/cve/cve-2026-8206/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-8206</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 GMT</pubDate>
      <description>The Kirki plugin for WordPress is vulnerable to unauthenticated privilege escalation via an account takeover flaw in the password reset process. Fix documented: 6.0.7 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-8073 · CVSS 7.5</title>
      <link>https://cvebrief.com/cve/cve-2026-8073/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-8073</guid>
      <pubDate>Wed, 20 May 2026 12:00:00 GMT</pubDate>
      <description>The Kirki – Freeform Page Builder, Website Builder &amp; Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the &apos;downloadZIP&apos; function in all versions up to, and including, 6 Fix documented: 6.0.7 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-3360 · CVSS 7.5</title>
      <link>https://cvebrief.com/cve/cve-2026-3360/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-3360</guid>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <description>The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to, and including, 3 Fix documented: 3.9.8 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-25406 · CVSS 8.8 · Tutor LMS Pro</title>
      <link>https://cvebrief.com/cve/cve-2026-25406/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-25406</guid>
      <pubDate>Fri, 27 Mar 2026 12:00:00 GMT</pubDate>
      <description>Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse Fix documented: 3.9.9 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-0953 · CVSS 9.8 · Tutor LMS Pro</title>
      <link>https://cvebrief.com/cve/cve-2026-0953/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-0953</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <description>An authentication bypass in the Tutor LMS Pro plugin for WordPress allows unauthenticated attackers to log in as any user, including administrators, via the Social Login addon. Fix documented: 3.9.6 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-13673 · CVSS 7.5</title>
      <link>https://cvebrief.com/cve/cve-2025-13673/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2025-13673</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <description>The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the &apos;coupon_code&apos; parameter in all versions up to, and including, 3 Fix documented: 3.9.7 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-1375 · CVSS 8.1</title>
      <link>https://cvebrief.com/cve/cve-2026-1375/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2026-1375</guid>
      <pubDate>Tue, 03 Feb 2026 12:00:00 GMT</pubDate>
      <description>The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3 Fix documented: 3.9.6 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-58993 · CVSS 7.6 · Tutor LMS</title>
      <link>https://cvebrief.com/cve/cve-2025-58993/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2025-58993</guid>
      <pubDate>Tue, 09 Sep 2025 12:00:00 GMT</pubDate>
      <description>Improper Neutralization of Special Elements used in an SQL Command (&apos;SQL Injection&apos;) vulnerability in Themeum Tutor LMS allows SQL Injection Fix documented: 3.8.0 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-6184 · CVSS 8.8 · Tutor LMS Pro</title>
      <link>https://cvebrief.com/cve/cve-2025-6184/</link>
      <guid isPermaLink="false">cvebrief-themeum-CVE-2025-6184</guid>
      <pubDate>Wed, 13 Aug 2025 12:00:00 GMT</pubDate>
      <description>The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in the get_submitted_assignments() function in all versions up to, and including, 3 Fix documented: 3.7.1 (Wordfence). Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
