← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 11:52via Cyber Security News

Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution

Brief

A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than 100,000 sites that use the e-learning plugin, particularly installations that allow visitors to register as students.

Tracked as CVE-2026-78175, the vulnerability is rated 8. 8 out of 10 and affects Tutor LMS versions 4.

  • 7 and earlier. An attacker needs a subscriber-level account, but on sites with open registration, creating that account may be as simple as completing a student sign-up form.

Researchers noted that the bug can lead to remote code execution, meaning an attacker could run commands on the web server.

Wordfence said in a report shared with Cyber Security News (CSN) that its Argus research agent identified the issue on August 23, 2026, and the findings were validated the same day.

Read more on Cyber Security News→