Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution

A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than 100,000 sites that use the e-learning plugin, particularly installations that allow visitors to register as students. Tracked as CVE-2026-78175, the vulnerability is rated 8. 8 out of 10 and affects Tutor LMS versions 4. 0. 7 and earlier. An attacker needs a subscriber-level account, but on sites with open registration, creating that account may be as simple as completing a student sign-up form. Researchers noted that the bug can lead to remote code execution, meaning an attacker could run commands on the web server. Wordfence said in a report shared with Cyber Security News (CSN) that its Argus research agent identified the issue on August 23, 2026, and the findings were validated the same day.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Tutor LMS PHP Object Injection Flaw Lets Attackers Plant Web Shells on WordPress Sites

A critical vulnerability in the Tutor LMS WordPress plugin could allow low-privileged users to execute code remotely and plant web shells on vulnerable websites. Wordfence researchers, assisted by its Argus AI research agent, discovered the flaw on August 23, 2026. The issue affects Tutor LMS versions 4. 0. 7 and earlier, a widely used e-learning plugin installed on more than 100,000 WordPress sites. Tracked as CVE-2026-78175, the vulnerability received a CVSS score of 8. 8 out of 10. Themeum, the developer of Tutor LMS, fixed the issue in version 4. 0. 8, released on September 10, 2026. The vulnerability is particularly serious because an attacker only needs subscriber-level access. Many Tutor LMS websites allow students to register freely, which means an unauthenticated visitor may be able to create an account and then exploit the flaw.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

NVD-CVE-2026-78175 - National Institute of Standards and Technology (.gov)

NVD-CVE-2026-78175 National Institute of Standards and Technology (.gov)

·NVD
Read →

You've reached the end of current stories for this search.