← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 07:29via CyberPress

Tutor LMS PHP Object Injection Flaw Lets Attackers Plant Web Shells on WordPress Sites

Brief

A critical vulnerability in the Tutor LMS WordPress plugin could allow low-privileged users to execute code remotely and plant web shells on vulnerable websites.

Wordfence researchers, assisted by its Argus AI research agent, discovered the flaw on August 23, 2026. The issue affects Tutor LMS versions 4.

  • 7 and earlier, a widely used e-learning plugin installed on more than 100,000 WordPress sites.

Tracked as CVE-2026-78175, the vulnerability received a CVSS score of 8. 8 out of 10. Themeum, the developer of Tutor LMS, fixed the issue in version 4.

  • 8, released on September 10, 2026.

The vulnerability is particularly serious because an attacker only needs subscriber-level access. Many Tutor LMS websites allow students to register freely, which means an unauthenticated visitor may be able to create an account and then exploit the flaw.

Read more on CyberPress→