← Back to overview

A critical vulnerability (CVE-2026-19092) has been identified in the Tutor LMS WordPress plugin prior to version 4.0.6. The flaw allows unauthenticated users to overwrite internal template variables during rendering, enabling them to invoke arbitrary zero-argument PHP functions and retrieve their output. This represents a significant remote code execution risk as no authentication is required to exploit the vulnerability. The issue stems from insufficient input validation when processing request data during template rendering. WordPress site administrators running Tutor LMS should update to version 4.0.6 or later immediately to mitigate the risk.

Affected products

  • Tutor LMS WordPress Plugin

Related CVE's

  • CVE-2026-19092

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities