
Tutor LMS PHP Object Injection Flaw Lets Attackers Plant Web Shells on WordPress Sites
A critical vulnerability in the Tutor LMS WordPress plugin could allow low-privileged users to execute code remotely and plant web shells on vulnerable websites. Wordfence researchers, assisted by its Argus AI research agent, discovered the flaw on August 23, 2026. The issue affects Tutor LMS versions 4.0.7 and earlier, a widely used e-learning plugin installed […]
The post Tutor LMS PHP Object Injection Flaw Lets Attackers Plant Web Shells on WordPress Sites appeared first on Cyber Security News.