Detects Tutor LMS Pro plugin at version 3.9.5 or earlier where the Social Login addon accepts a user-supplied email in the OAuth callback without verifying it matches the email from the validated token claims. An unauthenticated attacker can authenticate with their own OAuth account but substitute the victim’s email, logging in as any user including administrators.
Is your app exploitable through CVE-2026-0953?
Scan your domain free