ZeroHour
Product

Tutor LMS

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution

A CVSS 8.8 PHP object injection flaw (CVE-2026-78175) in Tutor LMS exposes 100,000+ WordPress sites to subscriber-level remote code execution; patched in 4.0.8.

CVE-2026-78175 (CVSS 8.8) affects Tutor LMS versions 4.0.7 and earlier, a WordPress e-learning plugin used on more than 100,000 sites. The tutor_save_withdraw_account AJAX handler verifies only a nonce and not user roles, allowing subscriber-level users to trigger PHP object injection that writes arbitrary files and can achieve remote code execution. Wordfence's Argus research agent identified the flaw on August 23, 2026, with a firewall rule available August 25 and a free rule scheduled for September 24. Version 4.0.8, released September 10, 2026, adds instructor-only permission checks and removes the unsafe data processing; no in-the-wild exploitation has been reported.

Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability

Wordfence disclosed CVE-2026-78175, an authenticated PHP object injection chain enabling RCE in Tutor LMS affecting 100,000+ WordPress sites; fixed in 4.0.8.

Wordfence Argus discovered on August 23, 2026, that Tutor LMS 4.0.7 and earlier mishandle esc_sql() on withdrawal-account data stored via update_user_meta(), creating a serialized-length mismatch exploitable for PHP object injection through the tutor_save_withdraw_account AJAX handler. Any subscriber can reach the endpoint because it checks a nonce but no capability, and a property-oriented programming chain using Guzzle's FileCookieJar allows writing a PHP payload to the uploads directory for remote code execution. Themeum shipped version 4.0.8 on September 10 with a role check, input validation, and a field whitelist; Wordfence rated the issue CVSS 8.8.

GBHackersupdated · 4h agofirst · 6h agoVulnerability 9 sourcesCVE-2026-781752· 1 read

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

Wordfence found a PHP object injection flaw in Tutor LMS letting subscriber-level attackers achieve remote code execution on 100,000+ WordPress sites.

Wordfence Argus researchers discovered a PHP object injection vulnerability in the Tutor LMS WordPress plugin, which is installed on more than 100,000 sites. Subscriber-level authenticated attackers could chain the flaw to remote code execution. The issue is fixed in Tutor LMS version 4.0.8, and no exploitation has been reported so far.

Wordfenceupdated · 4h agofirst · 19h agoVulnerability 9 sources1

Related CVEs

  • PHP Object Injection to RCE in Tutor LMS WordPress Plugin (≤ 4.0.7)
    Tutor LMS, a WordPress eLearning plugin, suffers from a PHP object injection flaw (CWE-502) in the `tutor_save_withdraw_account` AJAX handler, which accepts attacker-controlled `withdraw_method_field` values with no capability check beyond a nonce and stores them via `update_user_meta()` in a way that corrupts serialized string lengths. An authenticated user with subscriber-level privileges (or an unauthenticated attacker, if open user registration is enabled) who holds a valid nonce can therefore make `unserialize()` over-read into attacker-controlled bytes and inject an arbitrary serialized object. By chaining the plugin's bundled PayPal Composer autoloader with the `GuzzleHttp\Cookie\FileCookieJar` gadget, the attacker achieves remote code execution, writing attacker-controlled content to an attacker-specified filename on the server. All sites running Tutor LMS up to and including version 4.0.7 with the monetization feature enabled are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
    · Themeum Tutor LMS – eLearning and online course solution plugin for WordPress All versions up to and including 4.0.7large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.