Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
Brief
A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than 100,000 sites that use the e-learning plugin, particularly installations that allow visitors to register as students.
Tracked as CVE-2026-78175, the vulnerability is rated 8. 8 out of 10 and affects Tutor LMS versions 4.
- 7 and earlier. An attacker needs a subscriber-level account, but on sites with open registration, creating that account may be as simple as completing a student sign-up form.
Researchers noted that the bug can lead to remote code execution, meaning an attacker could run commands on the web server.
Wordfence said in a report shared with Cyber Security News (CSN) that its Argus research agent identified the issue on August 23, 2026, and the findings were validated the same day.
