Skip to content
Over 100,000 WordPress Sites Vulnerable to Remote Code Execution

Over 100,000 WordPress Sites Vulnerable to Remote Code Execution

First seen 18 Sep 2026, 00:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 02:00 UTC
  • Over 100,000 WordPress sites are affected by a critical vulnerability in Tutor LMS.
  • The vulnerability allows remote code execution via PHP Object Injection due to insecure input handling.
  • Users are advised to update to Tutor LMS version 4.0.8 to mitigate the risk.

A critical vulnerability affecting the Tutor LMS plugin allows for remote code execution on over 100,000 WordPress sites. The vulnerability stems from insecure handling of user input in the plugin's withdraw account management feature, which can be exploited via PHP Object Injection. Wordfence discovered and reported the issue on August 23, 2026, and a patch was released by the Themeum team on September 10, 2026. Users of Wordfence Premium received a firewall rule to mitigate the threat on August 25, while free users will receive protection on September 24, 2026. Site owners are urged to update to the latest version of Tutor LMS, version 4.0.8, to secure their sites against potential exploitation. The vulnerability has been validated and disclosed responsibly through Wordfence's Vulnerability Management Portal.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-23
Vulnerability reported to Themeum
Wordfence disclosed a critical vulnerability in Tutor LMS, impacting over 100,000 sites.
Wordfence
2026-08-25
Firewall rule deployed for Premium users
Wordfence Premium users received a firewall rule to protect against the vulnerability.
Wordfence
2026-09-10
Patch released by Themeum
Themeum released Tutor LMS version 4.0.8, which includes a fix for the vulnerability.
Wordfence
2026-09-24
Free users to receive firewall protection
Wordfence will deploy a firewall rule for free users to protect against the vulnerability.
Wordfence

More articles in this cluster (3)

Following this threat?

Track Themeum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed