Remote Code Execution Vulnerability in Tutor LMS Plugin by WordPress
CVE-2026-19092
Key Information:
Badges
What is CVE-2026-19092?
CVE-2026-19092 is a serious remote code execution vulnerability found in the Tutor LMS plugin for WordPress, specifically affecting versions prior to 4.0.6. The Tutor LMS plugin serves as a learning management system that allows users to create and manage online courses, offering functionality such as quizzes, grading, and course tracking. The vulnerability arises from improper handling of request data, which can result in internal variables being overwritten during template rendering. This flaw permits unauthenticated users to invoke arbitrary PHP functions with zero arguments, exposing systems to significant risks. If exploited, this can lead to unauthorized control over the affected WordPress site, potentially allowing attackers to manipulate site content, access sensitive information, or launch further attacks on the server.
Potential impact of CVE-2026-19092
-
Unauthorized Access: Attackers can exploit this vulnerability to gain unauthorized access to the site's resources, potentially allowing them to inject malicious code or alter course content, affecting the integrity of the online learning environment.
-
Data Breach Risk: Given that Tutor LMS may handle sensitive user data, such as personal information and payment details, exploiting this vulnerability could lead to significant data breaches, compromising user privacy and trust.
-
Wider System Compromise: Once an attacker gains control through this vulnerability, they may leverage it to establish a foothold within the overall server environment, increasing the potential for further attacks or the deployment of malware, thus expanding the attack surface.
Affected Version(s)
Tutor LMS 2.1.3 < 4.0.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved