Tutor LMS Bug Exposes 100,000 WordPress Sites to Subscriber RCE

Élevé · Wordfence ·

WordPress

En bref

  • Wordfence disclosed a Tutor LMS vulnerability affecting roughly 100,000 WordPress installations.
  • A subscriber account is enough to attempt PHP object injection that can lead to remote code execution.
  • No CVE was assigned; the fixed release is Tutor LMS 4.0.8.
  • Unpatched sites face high risk until they upgrade or mitigate.

A September 2026 disclosure from Wordfence details a high-severity security weakness in Tutor LMS, a popular learning management plugin for WordPress. The issue touches approximately 100,000 WordPress installations. It allows an authenticated user with only subscriber-level permissions to abuse PHP object injection and achieve remote code execution. No CVE identifier was published alongside the finding.

The attack path is notable because subscriber accounts are common and often treated as low risk. On vulnerable sites, someone who can register or obtain such an account may be able to supply malicious input that the plugin unserializes insecurely, leading to code execution on the server. That could let an intruder install backdoors, alter content, steal data, or pivot deeper into the hosting environment.

Tutor LMS maintainers released version 4.0.8 to address the flaw. Wordfence's discovery and the availability of a patch mean the primary mitigation is straightforward: upgrade. Sites still running older releases remain exposed, and because the vulnerability can be exploited remotely after authentication, delaying updates increases the chance of compromise.

The scale is significant for K-12 and government WordPress deployments. Many districts use LMS plugins for course content, student resources, and staff training. A single unpatched site could become an entry point into a broader network, especially if the WordPress installation shares credentials, databases, or hosting with other services.

What to watch: scan for Tutor LMS versions below 4.0.8, monitor for unexpected admin creation, file changes, or outbound connections, and review subscriber registrations for suspicious activity. Since no CVE was assigned, some vulnerability scanners may not flag it by CVE, so version checks and vendor advisories are essential.

À faire maintenant

  1. Update Tutor LMS to 4.0.8 or later immediately; if you cannot patch right away, disable the plugin until the update can be applied.
  2. Audit WordPress accounts with the subscriber role, remove stale or unnecessary users, and disable open registration if it is not required.
  3. Check for signs of compromise: new administrator accounts, modified plugin or theme files, unexpected scheduled tasks, and unusual outbound connections.
  4. Apply virtual patching or WAF rules from Wordfence or your hosting provider to block PHP object injection attempts targeting Tutor LMS.
  5. If compromise is suspected, rotate WordPress salts and keys, reset administrator passwords, and revoke active sessions.
  6. Monitor logs for POST requests to Tutor LMS endpoints from subscriber accounts, especially requests containing serialized payloads.
  7. Maintain tested backups and enable automatic updates for security releases to reduce future exposure windows.

Source originale

Wordfence

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber