Vulnerability
Published 2026-09-12
Verified 2026-09-19

Tutor LMS <= 4.0.7 PHP object injection to RCE (CVE-2026-78175, CVSS 8.8); fix 4.0.8

Wordfence CNA (CVE published 12 September 2026; disclosed 11 Sep; vendor notified 23 Aug) documents CVE-2026-78175 in Themeum Tutor LMS (WordPress e-learning plugin): authenticated subscriber+ PHP object injection via the withdraw_method_field parameter of the tutor_save_withdraw_account AJAX handler (CWE-502). The handler relies on a nonce only (no capability/role check) and passes attacker-controlled values through esc_sql() before update_user_meta(); on retrieve, unserialize() over-reads into attacker-controlled bytes, enabling arbitrary object injection. Wordfence describes a GuzzleHttp\Cookie\FileCookieJar POP chain via the plugin's bundled PayPal Composer autoloader (TUTOR\RestAPI spl_autoload_register), writing attacker-controlled content to an attacker-chosen filename — remote code execution on the web server. CVSS 3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Affected: all versions ≤ 4.0.7; unauthenticated pathway when user registration is enabled (common for student/teacher sign-up) and monetization is enabled. CISA ADP SSVC (15 Sep): Exploitation none / Automatable no / Technical Impact total. No in-the-wild exploitation claimed in the CNA. Patch: Tutor LMS 4.0.8 (wire reporting: Themeum release ~10 Sep 2026). Credits: Chloe Chamberland / Wordfence Argus. Primary: Wordfence threat-intel / CVE record; wire: Cyber Security News 18 Sep.

Product
Themeum Tutor LMS (WordPress plugin — eLearning / online course solution)
Versions
All versions <= 4.0.7 affected; fixed in 4.0.8
CVSS
(CVSS 3.1 High, Wordfence)
Exploited in Australia?
unknown
Patch to
Upgrade Tutor LMS to 4.0.8 or later; disable open student registration / monetization withdrawal features until patched; review subscriber accounts and web-accessible uploads

Primary: Wordfence — Tutor LMS <= 4.0.7 PHP Object Injection to RCE (CVE-2026-78175) · Vendor: CVE.org — CVE-2026-78175 (Wordfence CNA) · CVE: CVE-2026-78175 · WordPress.org plugin trac — tutor changeset 3690454 (4.0.8 fix)

vulnerabilities cloud