100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
High · Wordfence ·
WordPress
What happened
PHP object injection flaw in the Tutor LMS WordPress plugin lets subscriber-level accounts achieve remote code execution; over 100,000 sites affected. Fixed in version 4.0.8.
What to do now
Update Tutor LMS to 4.0.8 now; if you cannot patch immediately, deactivate the plugin. Then restrict open subscriber registration, audit new/low-privilege accounts, review logs, and scan for webshells.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.