100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

High · Wordfence ·

WordPress

What happened

PHP object injection flaw in the Tutor LMS WordPress plugin lets subscriber-level accounts achieve remote code execution; over 100,000 sites affected. Fixed in version 4.0.8.

What to do now

Update Tutor LMS to 4.0.8 now; if you cannot patch immediately, deactivate the plugin. Then restrict open subscriber registration, audit new/low-privilege accounts, review logs, and scan for webshells.

Original source

Wordfence

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news