100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
Wordfence found a PHP object injection flaw in Tutor LMS letting subscriber-level attackers achieve remote code execution on 100,000+ WordPress sites.
Wordfence Argus researchers discovered a PHP object injection vulnerability in the Tutor LMS WordPress plugin, which is installed on more than 100,000 sites. Subscriber-level authenticated attackers could chain the flaw to remote code execution. The issue is fixed in Tutor LMS version 4.0.8, and no exploitation has been reported so far.
- Affects the Tutor LMS plugin installed on over 100,000 WordPress sites.
- Subscriber-level attackers can escalate to remote code execution via PHP object injection.
- Discovered by Wordfence Argus.
- Fixed in Tutor LMS version 4.0.8.
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible. The post 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS appeared first on Wordfence.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.