Remote Code Execution Vulnerability in Tutor LMS Plugin by WordPress
CVE-2026-19092

9.8CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
27 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-19092?

CVE-2026-19092 is a serious remote code execution vulnerability found in the Tutor LMS plugin for WordPress, specifically affecting versions prior to 4.0.6. The Tutor LMS plugin serves as a learning management system that allows users to create and manage online courses, offering functionality such as quizzes, grading, and course tracking. The vulnerability arises from improper handling of request data, which can result in internal variables being overwritten during template rendering. This flaw permits unauthenticated users to invoke arbitrary PHP functions with zero arguments, exposing systems to significant risks. If exploited, this can lead to unauthorized control over the affected WordPress site, potentially allowing attackers to manipulate site content, access sensitive information, or launch further attacks on the server.

Potential impact of CVE-2026-19092

  1. Unauthorized Access: Attackers can exploit this vulnerability to gain unauthorized access to the site's resources, potentially allowing them to inject malicious code or alter course content, affecting the integrity of the online learning environment.

  2. Data Breach Risk: Given that Tutor LMS may handle sensitive user data, such as personal information and payment details, exploiting this vulnerability could lead to significant data breaches, compromising user privacy and trust.

  3. Wider System Compromise: Once an attacker gains control through this vulnerability, they may leverage it to establish a foothold within the overall server environment, increasing the potential for further attacks or the deployment of malware, thus expanding the attack surface.

Affected Version(s)

Tutor LMS 2.1.3 < 4.0.6

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman
WPScan
.