Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
A CVSS 8.8 PHP object injection flaw (CVE-2026-78175) in Tutor LMS exposes 100,000+ WordPress sites to subscriber-level remote code execution; patched in 4.0.8.
CVE-2026-78175 (CVSS 8.8) affects Tutor LMS versions 4.0.7 and earlier, a WordPress e-learning plugin used on more than 100,000 sites. The tutor_save_withdraw_account AJAX handler verifies only a nonce and not user roles, allowing subscriber-level users to trigger PHP object injection that writes arbitrary files and can achieve remote code execution. Wordfence's Argus research agent identified the flaw on August 23, 2026, with a firewall rule available August 25 and a free rule scheduled for September 24. Version 4.0.8, released September 10, 2026, adds instructor-only permission checks and removes the unsafe data processing; no in-the-wild exploitation has been reported.