All verified exploits

CVE-2026-0953 Social Login OAuth Authentication Bypass

Deterministic critical Tutor LMS Added cve-verified-cve-2026-0953

Detects Tutor LMS Pro plugin at version 3.9.5 or earlier where the Social Login addon accepts a user-supplied email in the OAuth callback without verifying it matches the email from the validated token claims. An unauthenticated attacker can authenticate with their own OAuth account but substitute the victim’s email, logging in as any user including administrators.

Is your app exploitable through CVE-2026-0953?

Scan your domain free