PHP Object Injection Vulnerability in Tutor LMS eLearning Plugin for WordPress
CVE-2026-78175

8.8HIGH

What is CVE-2026-78175?

The Tutor LMS plugin for WordPress contains a PHP Object Injection vulnerability found in the AJAX handler tutor_save_withdraw_account. This issue arises from a lack of capability checks and inadequate handling of user-inputted data, permitting authenticated attackers with subscriber-level access or higher to execute arbitrary code on the server. By manipulating the withdraw_method_field parameter, attackers can inject a serialized object, leveraging the plugin's PayPal Composer autoloader to control file writing operations. This flaw is especially critical when user registration is enabled, as it presents an unauthenticated pathway for exploitation, making it an attractive target for malicious actors.

Affected Version(s)

Tutor LMS – eLearning and online course solution 0 <= 4.0.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chloe Chamberland
Wordfence Argus
.