Remote Code Execution Vulnerability in Tutor LMS Plugin by WordPress
CVE-2026-19092
Key Information:
Badges
What is CVE-2026-19092?
The Tutor LMS WordPress plugin, prior to version 4.0.6, contains a significant security flaw that permits unauthenticated users to manipulate request data, leading to the overwriting of internal variables during template rendering. This vulnerability enables attackers to invoke arbitrary zero-argument PHP functions, potentially exposing sensitive outputs and compromising system integrity. It is essential for site administrators using affected versions to update promptly to mitigate this risk.
Affected Version(s)
Tutor LMS 2.1.3 < 4.0.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved