A high-severity vulnerability, CVE-2026-78175 (CVSS 8.8), in the Tutor LMS WordPress plugin can let authenticated subscriber-level users execute code on affected servers. Versions 4.0.7 and earlier inadequately protect a withdrawal-account AJAX handler: it validates a nonce but does not enforce proper authorization, allowing crafted data to be stored in user records and later unsafely deserialized. Exploitation chains WordPress serialization-length desynchronization with a bundled Guzzle FileCookieJar deserialization gadget chain; sites with open student registration are particularly exposed because attackers can create the required account, provided monetization is enabled.
Themeum addressed the issue in Tutor LMS 4.0.8 by restricting the handler to instructors, removing unsafe esc_sql() usage, validating withdrawal methods, and allowlisting form-field keys. Organizations using the plugin should update immediately and review user accounts, upload directories, administrator accounts, and web-server logs for suspicious activity. No active exploitation has been confirmed publicly.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Wordfence published its advisory describing CVE-2026-78175, which affects Tutor LMS versions 4.0.7 and earlier and can allow an authenticated subscriber to achieve remote code execution.
Themeum released Tutor LMS 4.0.8, fully remediating CVE-2026-78175. The update adds an instructor authorization check, removes unsafe processing, validates withdrawal methods, and restricts accepted form fields.
A firewall rule intended to protect against CVE-2026-78175 was made available to certain users as an additional mitigation layer.
Themeum acknowledged the report concerning CVE-2026-78175 in the Tutor LMS WordPress plugin.
Wordfence's Argus research agent identified CVE-2026-78175, a high-severity PHP object-injection flaw in Tutor LMS, and the Wordfence Threat Intelligence team validated the finding the same day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.