
Tutor LMS Elementor Addons Security & Risk Analysis
wordpress.org/plugins/tutor-lms-elementor-addonsGet 35+ Elementor widgets to create an entire eLearning site with Tutor LMS and design custom course pages, course carousels, listings, and more.
Is Tutor LMS Elementor Addons Safe to Use in 2026?
Generally Safe
Score 95/100Tutor LMS Elementor Addons has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "tutor-lms-elementor-addons" v3.0.2 presents a mixed security posture. On the positive side, the static analysis shows a limited attack surface with only one AJAX handler and no exposed REST API routes, shortcodes, or cron events. The code also demonstrates some good practices with 80% of SQL queries using prepared statements and a high percentage of output escaping (70%). Furthermore, there are no critical or high severity taint flows, and no external HTTP requests are made, reducing the risk of certain types of attacks.
However, significant concerns are raised by the plugin's vulnerability history. With a total of 5 known CVEs, all of which are medium severity and primarily related to Cross-site Scripting and Missing Authorization, this indicates a pattern of past security weaknesses. The fact that all these historical vulnerabilities are now patched is a positive sign, but the prevalence of these specific types of vulnerabilities suggests potential recurring issues in how user input is handled and authorization is enforced. The complete absence of nonce checks and only a single capability check across all entry points are also considerable weaknesses that could be exploited if an attacker can trigger the AJAX handler.
In conclusion, while the current version shows improvements in reducing attack vectors and sanitizing some outputs, the history of XSS and authorization vulnerabilities, coupled with the lack of robust nonce and capability checks on its single entry point, leaves room for potential exploitation. The plugin has a decent foundation but requires vigilance, especially regarding input validation and authorization logic to prevent a recurrence of past vulnerabilities.
Key Concerns
- Missing nonce checks on AJAX handler
- Only 1 capability check for 1 entry point
- Significant past vulnerabilities (XSS, Missing Auth)
- 70% output escaping (potential for unescaped output)
Tutor LMS Elementor Addons Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Tutor LMS Elementor Addons <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tutor LMS Elementor Addons <= 2.1.5 - Missing Authorization
Tutor LMS Elementor Addons <= 2.1.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation
Tutor LMS Elementor Addons <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Course Carousel Widget
Tutor LMS Elementor Addons <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tutor LMS Elementor Addons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tutor LMS Elementor Addons Attack Surface
AJAX Handlers 1
WordPress Hooks 27
Maintenance & Trust
Tutor LMS Elementor Addons Maintenance & Trust
Maintenance Signals
Community Trust
Tutor LMS Elementor Addons Alternatives
Tutor LMS – eLearning and online course solution
tutor
A complete WordPress LMS plugin to create any eLearning website easily.
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am …
LearnPress – Course Wishlist
learnpress-wishlist
LearnPress Wishlist add wishlist feature to your LearnPress course in your site.
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
lifterlms
Complete e-learning platform to sell online courses, protect lessons, offer memberships, and quiz students. WP Learning Management System.
MasterStudy LMS WordPress Plugin – for Online Courses and Education
masterstudy-lms-learning-management-system
Learning Management System and eLearning plugin for WordPress. Create easily LMS WordPress website, add and sell Courses, Lessons, Quizzes online.
Tutor LMS Elementor Addons Developer Profile
14 plugins · 675K total installs
How We Detect Tutor LMS Elementor Addons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tutor-lms-elementor-addons/assets/css/tutor-elementor-icons.min.css/wp-content/plugins/tutor-lms-elementor-addons/assets/css/font-awesome.min.css/wp-content/plugins/tutor-lms-elementor-addons/assets/css/slick.min.css/wp-content/plugins/tutor-lms-elementor-addons/assets/css/slick-theme.css/wp-content/plugins/tutor-lms-elementor-addons/assets/css/tutor-elementor.min.css/wp-content/plugins/tutor-lms-elementor-addons/assets/js/slick.min.js/wp-content/plugins/tutor-lms-elementor-addons/assets/js/tutor-elementor.js/wp-content/plugins/tutor-lms-elementor-addons/assets/css/installer.css+1 moreETLMS_ASSETS . 'js/slick.min.js'ETLMS_ASSETS . 'js/tutor-elementor.js'ETLMS_ASSETS . 'js/installer.min.js'tutor-lms-elementor-addons/assets/css/tutor-elementor-icons.min.css?ver=tutor-lms-elementor-addons/assets/css/font-awesome.min.css?ver=tutor-lms-elementor-addons/assets/css/slick.min.css?ver=tutor-lms-elementor-addons/assets/css/slick-theme.css?ver=tutor-lms-elementor-addons/assets/css/tutor-elementor.min.css?ver=tutor-lms-elementor-addons/assets/js/slick.min.js?ver=tutor-lms-elementor-addons/assets/js/tutor-elementor.js?ver=tutor-lms-elementor-addons/assets/css/installer.css?ver=tutor-lms-elementor-addons/assets/js/installer.min.js?ver=HTML / DOM Fingerprints
tutor-elementor-widgettutor-elementor-course-bundletutor-elementor-content-visibilitytutor-elementor-course-detailstutor-elementor-quiz-details<!-- TODO remove in next release. Handle it by bundle addon. -->data-tutor-elementor-course-bundledata-tutor-elementor-content-visibilitydata-tutor-elementor-course-detailsdata-tutor-elementor-quiz-detailsetlmsUtilitytutorElementorData