ZeroHour
Vendor

Guzzle

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability

Wordfence disclosed CVE-2026-78175, an authenticated PHP object injection chain enabling RCE in Tutor LMS affecting 100,000+ WordPress sites; fixed in 4.0.8.

Wordfence Argus discovered on August 23, 2026, that Tutor LMS 4.0.7 and earlier mishandle esc_sql() on withdrawal-account data stored via update_user_meta(), creating a serialized-length mismatch exploitable for PHP object injection through the tutor_save_withdraw_account AJAX handler. Any subscriber can reach the endpoint because it checks a nonce but no capability, and a property-oriented programming chain using Guzzle's FileCookieJar allows writing a PHP payload to the uploads directory for remote code execution. Themeum shipped version 4.0.8 on September 10 with a role check, input validation, and a field whitelist; Wordfence rated the issue CVSS 8.8.

GBHackersupdated · 5h agofirst · 7h agoVulnerability 9 sourcesCVE-2026-781752· 1 read

Related CVEs

  • PHP Object Injection to RCE in Tutor LMS WordPress Plugin (≤ 4.0.7)
    Tutor LMS, a WordPress eLearning plugin, suffers from a PHP object injection flaw (CWE-502) in the `tutor_save_withdraw_account` AJAX handler, which accepts attacker-controlled `withdraw_method_field` values with no capability check beyond a nonce and stores them via `update_user_meta()` in a way that corrupts serialized string lengths. An authenticated user with subscriber-level privileges (or an unauthenticated attacker, if open user registration is enabled) who holds a valid nonce can therefore make `unserialize()` over-read into attacker-controlled bytes and inject an arbitrary serialized object. By chaining the plugin's bundled PayPal Composer autoloader with the `GuzzleHttp\Cookie\FileCookieJar` gadget, the attacker achieves remote code execution, writing attacker-controlled content to an attacker-specified filename on the server. All sites running Tutor LMS up to and including version 4.0.7 with the monetization feature enabled are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
    · Themeum Tutor LMS – eLearning and online course solution plugin for WordPress All versions up to and including 4.0.7large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.