Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-19092: Tutor LMS plugin lets anyone run code on your site

CVE-2026-19092 · published 7 days ago
Summary

The Tutor LMS add‑on for WordPress (versions before 4.0.6) lets data sent from a web request replace internal variables while the plugin builds pages. This means a stranger can cause the server to run any built‑in command that takes no arguments and see the result. Update the plugin to the latest version or remove it until it is upgraded.

Original advisory text
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argu...
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS 1%
Type
CWE-74Injection
Timeline
Published27 Aug 2026
Updated2 Sep 2026
First seen27 Aug 2026
Sources
Monitor software like this
Free during beta