CVE-2026-78175 is a PHP object-injection vulnerability in Themeum Tutor LMS for WordPress through version 4.0.7. The withdrawal-account AJAX functionality accepts attacker-controlled withdrawal fields while validating only a nonce and not enforcing a capability or role requirement. Its processing of percent characters before serialization and subsequent restoration creates an inconsistent serialized string length. Because attacker-controlled field names are incorporated as insufficiently constrained array keys, unsafe deserialization can consume attacker-controlled data beyond the declared string boundary and inject an arbitrary serialized object stream. A bundled GuzzleHttp Cookie FileCookieJar property-oriented programming chain can then write attacker-controlled content to an attacker-selected server-side file, permitting remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity (CVSS 8.8) authenticated PHP object-injection vulnerability in the Tutor LMS WordPress plugin's withdrawal-account AJAX handler. Insufficient authorization lets a subscriber with a valid nonce submit crafted withdrawal-account data; unsafe deserialization can ultimately be leveraged to write an attacker-controlled PHP file to a web-accessible directory and achieve remote code execution as the web-server user.
A high-severity (CVSS 8.8) authenticated remote-code-execution vulnerability in the Tutor LMS WordPress plugin. Insufficient authorization in the withdrawal-account AJAX handler permits subscriber-level users with a valid nonce to submit crafted data, leading to PHP object injection and attacker-controlled file writing. A PHP file written to a web-accessible uploads directory can execute commands with the web server's permissions.
A high-severity (CVSS 8.8) PHP object-injection vulnerability in the Tutor LMS WordPress plugin that can lead to remote code execution. Improper use of esc_sql() before serialized user-meta storage creates a serialized-length desynchronization, while attacker-controlled POST keys enable injection of a serialized object stream. The bundled PayPal/Guzzle dependency provides a FileCookieJar deserialization gadget that can write an attacker-controlled PHP file. Exploitation requires subscriber-level authentication and the monetization feature enabled; open student registration can make this effectively unauthenticated.
An authenticated PHP object injection vulnerability in Tutor LMS for WordPress versions through 4.0.7. Insufficient authorization in an AJAX withdrawal-account handler, combined with unsafe serialization behavior, permits subscriber-level attackers to inject serialized objects and potentially achieve server-side remote code execution through a Guzzle FileCookieJar POP chain. Registration-enabled sites may expose an effectively unauthenticated path; the monetization feature must be enabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.