On August 23rd, 2026, Wordfence Argus, our AI research agent specializing in complex vulnerability chains, discovered a PHP Object Injection vulnerability in Tutor LMS, a WordPress e-learning plugin active on more than 100,000 websites. This vulnerability allows any authenticated attacker with subscriber-level access to achieve remote code execution on the server by exploiting an interaction between WordPress’s database abstraction layer and PHP’s serialization engine. Because Tutor LMS is built around student enrollment and most installations enable open registration by default, the authentication bar is effectively low for any visitor who can reach the site.
Our mission is to secure WordPress
Click here to continue reading this article.
