Tutor LMS – eLearning and online course solution
by Themeum · Education
Also makes 12 other plugins · 661.3K+ installs across the portfolio →
A complete WordPress LMS plugin to create any eLearning website easily.
84 health vs 66 average across 168 Education plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
148.7K
now · peak 190.5K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
22
releases in the last 12 months
2mo ago
latest release · v4.0.1
184
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 26% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2019-07-16 · 1,454 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ guezs1mo ago
Ha cambiado todo. Los menús están en inglés. Las personalizaciones no funcionan. Los usuarios están desconcertados y perdidos.
Read on wp.org ↗ - ★★★★★ lazarmld2mo ago
It’s great plugin and all, but this auto-update to 4.0 version and breaking everyones sites is a bold move. And then closing option to open a ticket for a free plugin is even bolder. Well played Tutor.Edit: they have open the support threads, you get one star back This topic was modified 1 week, 2 days ago by lazarmld.
Read on wp.org ↗ - ★★★★★ susanbastin4mo ago
Support team is very helpful, especially Mr. Rashed helped me a lot.
Read on wp.org ↗ - ★★★★★ lashram5mo ago
Having issues with TutorLMS on my site and the 24/7 support isn’t live, I wanted to work through my issues in real time and their only offer was for me to provide access to my admin. Absolutely not! I don’t trust anyone with admin access unsupervised! Luckily it’s opensource and I have some skills …
Read on wp.org ↗ - ★★★★★ karanu1237mo ago
I bought the Tutor Pro app, but had challenges installing the theme. I applaud the support team for guiding me through the entire onboarding process and forsetting up the app and theme on my site. All I have to do is create my courses and edit the theme to my liking. Thank you, the support team.
Read on wp.org ↗ - ★★★★★ matteo raggi7mo ago
I tested many lms, dozens and it looks to eb the best to my eyes.
Read on wp.org ↗ - ★★★★★ altaira847mo ago
Sama darmowa wersja działała jako tako choć była bardzo toporna i ograniczona! Nie pozwalała nawet podejrzeć kursu w czasie jego tworzenia! To Żenujące! Prawdziwe problemy zaczęły się po instalacji PRO! Wszyscy klienci stracili historię zamówień kursów a tym samym dostęp do kursów za które zapłacili! Licencja nie działa a gwarantowana obsługa 24/7 ma w dup…e problemy klientów premium i nawet nie raczy udzielić pomocy w tym zakresie! Oczekiwanie na odpowiedź to od kilkunastu godzin do kilku dni! Człowiek zapłacił prawie tysiąc złotych i został sam z problemem! NIE POLECAM!
Read on wp.org ↗ - ★★★★★ rosterdotcom8mo ago
Posted many days ago about issues this plugin has and nothing. I’m not the only one. Others have posted with no responses. This plugin has potential but with the lack of support, well, it’s just useless. Do better!
Read on wp.org ↗
Known vulnerabilities
via Wordfence Intelligence79 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 4.9 Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter ↗2026-07-27 CVE-2026-15444 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.0.1 Patched in 4.0.2
- Medium · 6.5 Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array ↗2026-07-15 CVE-2026-15022 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.0.0 Patched in 4.0.1
- Medium · 4.3 Tutor LMS – eLearning and online course solution <= 3.9.13 - Unauthenticated Insecure Direct Object Reference ↗2026-07-06 CVE-2026-57694 Authorization Bypass Through User-Controlled Key Affects <= 3.9.13 Patched in 3.9.14
- 2026-07-02 CVE-2026-14306 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.9.13 Patched in 3.9.14
- Medium · 6.4 Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title ↗2026-06-30 CVE-2026-13443 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.9.13 Patched in 3.9.14
- Medium · 4.3 Tutor LMS <= 3.9.12 - Authenticated (Subscriber+) Insecure Direct Object Reference to Quiz Attemp Modification ↗2026-06-22 CVE-2026-12271 Authorization Bypass Through User-Controlled Key Affects <= 3.9.12 Patched in 3.9.13
- Medium · 4.9 Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter ↗2026-06-17 CVE-2026-10736 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.9.11 Patched in 3.9.12
- 2026-05-12 CVE-2026-6965 Authorization Bypass Through User-Controlled Key Affects <= 3.9.9 Patched in 3.9.10
- 2026-04-16 CVE-2026-6080 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.9.8 Patched in 3.9.9
- 2026-04-10 CVE-2026-3371 Authorization Bypass Through User-Controlled Key Affects <= 3.9.7 Patched in 3.9.8
- 2026-03-16 CVE-2025-32223 Authorization Bypass Through User-Controlled Key Affects <= 3.9.4 Patched in 3.9.5
- Medium · 4.3 Tutor LMS <= 3.9.7 - Missing Authorization ↗
- 2026-02-27 CVE-2025-13673 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.9.6 Patched in 3.9.7
- 2026-02-02 CVE-2026-1371 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.9.5 Patched in 3.9.6
- 2026-02-02 CVE-2026-1375 Authorization Bypass Through User-Controlled Key Affects <= 3.9.5 Patched in 3.9.6
- 2026-01-02 CVE-2025-47555 Authorization Bypass Through User-Controlled Key Affects <= 3.9.4 Patched in 3.9.5
- 2025-09-09 CVE-2025-58993 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.7.4 Patched in 3.8.0
- 2024-11-20 CVE-2024-10400 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.6 Patched in 2.7.7
- 2024-08-16 CVE-2024-43282 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.2 Patched in 2.7.3
- 2024-08-09 CVE-2024-43231 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.3 Patched in 2.7.4
- Medium · 5.3 Tutor LMS <= 2.7.3 - Missing Authorization ↗
- Medium · 4.3 Tutor LMS <= 2.7.2 - Cross-Site Request Forgery ↗
- 2024-07-10 CVE-2024-37947 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.2 Patched in 2.7.3
- 2024-06-27 CVE-2024-37266 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.7.1 Patched in 2.7.2
- 2024-06-06 CVE-2024-4902 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.1 Patched in 2.7.2
- 2024-06-06 CVE-2024-5438 Authorization Bypass Through User-Controlled Key Affects <= 2.7.1 Patched in 2.7.2
- 2024-05-15 CVE-2024-4279 Authorization Bypass Through User-Controlled Key Affects <= 2.7.0 Patched in 2.7.1
- 2024-05-15 CVE-2024-4318 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.0 Patched in 2.7.1
- Critical · 9.8 Tutor LMS <= 2.7.0 - Missing Authorization ↗
- 2024-04-24 CVE-2024-3994 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.6.2 Patched in 2.7.0
- 2024-03-11 CVE-2024-1751 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.6.1 Patched in 2.6.2
- 2024-02-20 CVE-2024-1128 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 2.6.0 Patched in 2.6.1
- Medium · 4.3 Tutor LMS <= 2.6.0 - Missing Authorization ↗
- 2023-12-05 CVE-2023-49829 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.4 Patched in 2.3.0
- 2023-09-25 CVE-2023-4805 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.4 Patched in 2.3.0
- 2023-05-30 CVE-2023-25800 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.2.0 Patched in 2.2.1
- 2023-05-30 CVE-2023-25990 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.10 Patched in 2.2.0
- Critical · 9.8 Tutor LMS <= 2.1.10 - Unauthenticated SQL Injection ↗2023-05-30 CVE-2023-25700 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.10 Patched in 2.2.0
- 2023-01-12 CVE-2023-0236 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.9 Patched in 2.0.10
- 2022-09-26 CVE-2022-2563 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.9 Patched in 2.0.10
- Medium · 6.1 Tutor LMS – eLearning and online course solution 2.0.0-2.0.8 - Reflected Cross-Site Scripting ↗2022-08-22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.0.0 - 2.0.8 Patched in 2.0.9
- 2021-12-27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.11 Patched in 1.9.12
- 2021-12-27 CVE-2021-25017 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.11 Patched in 1.9.12
- 2021-10-19 CVE-2021-24873 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.10 Patched in 1.9.11
- 2021-09-20 CVE-2021-24740 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.9.9 Patched in 1.9.9
- Medium · 6.1 Tutor LMS <= 1.9.5 - Cross-Site Scripting ↗2021-08-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.5 Patched in 1.9.6
- 2021-06-28 CVE-2021-24455 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.1 Patched in 1.9.2
- 2021-04-05 CVE-2021-24242 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 1.8.7 Patched in 1.8.8
- 2021-03-15 CVE-2021-24183 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.8.2 Patched in 1.8.3
- 2021-03-15 CVE-2021-24185 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.7.7 Patched in 1.7.7
- 2021-03-15 CVE-2021-24181 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.7.7 Patched in 1.7.7
- 2021-03-15 CVE-2021-24182 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.8.2 Patched in 1.8.3
- 2021-03-15 CVE-2021-24186 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.8.3 Patched in 1.8.3
- 2021-01-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.12 Patched in 1.9.13
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 45 languages, 4 at 90% or more
Plus 21 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-02-08 90K+ → 100K+ up after 230 days in tier
- 2024-06-23 80K+ → 90K+ up after 1 days in tier
- 2024-06-22 90K+ → 80K+ down after 2 days in tier
- 2024-06-20 80K+ → 90K+ up after 197 days in tier
- 2023-12-06 70K+ → 80K+ up after 238 days in tier
- 2023-04-12 60K+ → 70K+ up after 176 days in tier
- 2022-10-18 50K+ → 60K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 70K+ installs · 4.3★ · 5 shared tags A -
MasterStudy LMS WordPress Plugin – for Online Courses and Education 10K+ installs · 4.5★ · 5 shared tags A -
StepUp LMS — installs · 3.6★ · 5 shared tags B -
LearnPress – Course Wishlist 20K+ installs · 3.9★ · 4 shared tags B -
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes 10K+ installs · 4.8★ · 4 shared tags A
-
LearnPress – Prerequisites Courses 6K+ installs · 4.0★ · 4 shared tags B
Embed this report card
Drop a live Pulse card for Tutor LMS – eLearning and online course solution into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/tutor" width="480" height="300" style="border:0" loading="lazy" title="Tutor LMS – eLearning and online course solution — Plugin Pulse"></iframe> Tutor LMS – eLearning and online course solution: 100K+ active installs, 4.4★ (587 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/tutor