ZeroHour
Wordfencepublished ()ingested Chloe Chamberland1
Part of a story covered by 9 sources: “Hackers Plant PHP Webshells via WooCommerce Wholesale Lead Capture Flaw CVE-2026-27540; Wordfence Also Discloses RCE Bugs in The Events Calendar and Tutor LMS” — merged summary and timeline →

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

highVulnerabilityimportance 62
AI summary · glm-5.3-flash

Wordfence found a PHP object injection flaw in Tutor LMS letting subscriber-level attackers achieve remote code execution on 100,000+ WordPress sites.

Wordfence Argus researchers discovered a PHP object injection vulnerability in the Tutor LMS WordPress plugin, which is installed on more than 100,000 sites. Subscriber-level authenticated attackers could chain the flaw to remote code execution. The issue is fixed in Tutor LMS version 4.0.8, and no exploitation has been reported so far.

  • Affects the Tutor LMS plugin installed on over 100,000 WordPress sites.
  • Subscriber-level attackers can escalate to remote code execution via PHP object injection.
  • Discovered by Wordfence Argus.
  • Fixed in Tutor LMS version 4.0.8.
Full article

Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible. The post 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS appeared first on Wordfence.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.