Wordfence Over 100,000 WordPress Sites Vulnerable to Remote Code Execution
Article Content
- •Over 100,000 WordPress sites are affected by a critical vulnerability in Tutor LMS.
- •The vulnerability allows remote code execution via PHP Object Injection due to insecure input handling.
- •Users are advised to update to Tutor LMS version 4.0.8 to mitigate the risk.
A critical vulnerability affecting the Tutor LMS plugin allows for remote code execution on over 100,000 WordPress sites. The vulnerability stems from insecure handling of user input in the plugin's withdraw account management feature, which can be exploited via PHP Object Injection. Wordfence discovered and reported the issue on August 23, 2026, and a patch was released by the Themeum team on September 10, 2026. Users of Wordfence Premium received a firewall rule to mitigate the threat on August 25, while free users will receive protection on September 24, 2026. Site owners are urged to update to the latest version of Tutor LMS, version 4.0.8, to secure their sites against potential exploitation. The vulnerability has been validated and disclosed responsibly through Wordfence's Vulnerability Management Portal.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Themeum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…