← Back to the live CVE advisory feed

CVE-2026-78175: Tutor LMS – eLearning and online course solution

Severity
8.8 (HIGH)
Vendor
THEMEUM
Affected versions
0 through 4.0.7
Patch status
Unknown
Published
2026-09-12T08:16:24.507
Modified
2026-09-12T08:16:24.507

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sql()`, which replaces every `%` character with a 66-byte HMAC placeholder token before the data is serialized and stored via `update_user_meta()`; when the meta is later retrieved, the placeholder is collapsed back to a single `%`, leaving serialized string length declarations 65 bytes greater than the actual content, and because array keys originate from entirely unescaped POST field names, `unserialize()` over-reads into attacker-controlled bytes, allowing injection of an arbitrary serialized object stream. This makes it possible for authenticated attackers, with subscriber-level access and above, to achieve remote code execution on the server by triggering the `GuzzleHttp\Cookie\FileCookieJar` POP chain, reachable via the `spl_autoload_register` loader in `TUTOR\RestAPI` which loads the plugin's own bundled PayPal Composer autoloader, writing attacker-controlled content to an attacker-specified filename. This has an unauthenticated pathway when user registration is enabled, which is common for students and teachers to register, and it requires the monetization feature to be enabled.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 12, 2026 12:00 PM UTC
667 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-80462
Product identification pending
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-87985
mistral-vibe
Reporter: 6F8DE1F0-F67E-45A6-B68F-98777FDB759C
10
CRITICAL
VIEW RECORD
CVE-2026-87986
mistral-vibe
Reporter: 6F8DE1F0-F67E-45A6-B68F-98777FDB759C
10
CRITICAL
VIEW RECORD
CVE-2026-87987
mistral-vibe
Reporter: 6F8DE1F0-F67E-45A6-B68F-98777FDB759C
10
CRITICAL
VIEW RECORD
CVE-2026-87988
mistral-vibe
Reporter: 6F8DE1F0-F67E-45A6-B68F-98777FDB759C
10
CRITICAL
VIEW RECORD
CVE-2026-82617
Product identification pending PATCH
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-85706 EXPLOITED
Product identification pending PATCH
Reporter: CVE
10
CRITICAL
VIEW RECORD
CVE-2026-87719
Product identification pending PATCH
Reporter: CVE
9.9
CRITICAL
VIEW RECORD
CVE-2026-84390
FortiMonitorOnSight
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-71644
Product identification pending
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-62103
Everest Forms PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62105
ThemeREX Addons PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-79395
Product identification pending
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-53952
GetSimpleCMS-CE
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-78006
The Events Calendar
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-78159
The Events Calendar
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-38056
Product identification pending
Reporter: ICS-CERT
9.4
CRITICAL
VIEW RECORD
CVE-2026-89249
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-89253
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-89254
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-89255
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-89256
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-89258
hugo PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-89259
hugo PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-87984
mistral-vibe
Reporter: 6F8DE1F0-F67E-45A6-B68F-98777FDB759C
9.3
CRITICAL
VIEW RECORD
CVE-2026-89010
WN535M1 PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-72709
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-72710
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-54072
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-89243
AVideo
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-89212
Product identification pending PATCH
Reporter: SECURITY
9.2
CRITICAL
VIEW RECORD
CVE-2026-87983
mistral-vibe
Reporter: 6F8DE1F0-F67E-45A6-B68F-98777FDB759C
9.2
CRITICAL
VIEW RECORD
CVE-2026-3869
Modicon M580
Reporter: CYBERSECURITY
9.2
CRITICAL
VIEW RECORD
CVE-2026-54047
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-90456
Product identification pending
Reporter: ICS-CERT
9.2
CRITICAL
VIEW RECORD
CVE-2026-71416
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-78224
Product identification pending
Reporter: ICS-CERT
8.8
HIGH
VIEW RECORD
CVE-2026-89009
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-62102
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-62106
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-62107
Masteriyo – LMS PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-89266
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-78175
Tutor LMS – eLearning and online course solution
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-89250
AVideo
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-82578
Product identification pending
Reporter: ICS-CERT
8.7
HIGH
VIEW RECORD
CVE-2026-89013
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-89260
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-89262
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-72708
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-44715
Product identification pending
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-90444
Product identification pending
Reporter: ICS-CERT
8.7
HIGH
VIEW RECORD
CVE-2026-38058
Product identification pending
Reporter: ICS-CERT
8.6
HIGH
VIEW RECORD
CVE-2026-85979
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-70341
Product identification pending
Reporter: SECURE
8.5
HIGH
VIEW RECORD
CVE-2026-7863
Product identification pending PATCH
Reporter: ILETISIM
8.4
HIGH
VIEW RECORD
CVE-2026-89066
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
8.4
HIGH
VIEW RECORD
CVE-2026-54174
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.3
HIGH
VIEW RECORD
CVE-2026-89090
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
8.2
HIGH
VIEW RECORD
CVE-2026-90451
Product identification pending
Reporter: ICS-CERT
8.2
HIGH
VIEW RECORD
CVE-2026-49464
Product identification pending
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-8301
Product identification pending PATCH
Reporter: ILETISIM
7.8
HIGH
VIEW RECORD
CVE-2026-8303
Product identification pending PATCH
Reporter: ILETISIM
7.8
HIGH
VIEW RECORD
CVE-2026-89099
Product identification pending
Reporter: CNA
7.7
HIGH
VIEW RECORD
CVE-2026-62109
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-62112
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-90460
Product identification pending PATCH
Reporter: CVE
7.6
HIGH
VIEW RECORD
CVE-2026-90474
Product identification pending PATCH
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-87776
Product identification pending PATCH
Reporter: CE714D77-ADD3-4F53-AFF5-83D477B104BB
7.5
HIGH
VIEW RECORD
CVE-2026-68497
Product identification pending PATCH
Reporter: 36C7BE3B-2937-45DF-85EA-CA7133EA542C
7.5
HIGH
VIEW RECORD
CVE-2026-79393
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-54135
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-49846
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-50013
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-16482
rtMedia for WordPress, BuddyPress and bbPress
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-85200
GEO my WP
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-54240
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.4
HIGH
VIEW RECORD
CVE-2026-54241
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.4
HIGH
VIEW RECORD
CVE-2026-57842
Product identification pending
Reporter: DISCLOSURE
7.3
HIGH
VIEW RECORD
CVE-2026-82583
Product identification pending
Reporter: ICS-CERT
7.2
HIGH
VIEW RECORD
CVE-2026-87020
Product identification pending
Reporter: ICS-CERT
7.2
HIGH
VIEW RECORD
CVE-2026-47773
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.2
HIGH
VIEW RECORD
CVE-2026-89245
AVideo
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-89251
AVideo
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-89252
AVideo
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-89012
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-78807
Product identification pending
Reporter: CVE
7.1
HIGH
VIEW RECORD
CVE-2026-62089
Product identification pending
Reporter: AUDIT
7.1
HIGH
VIEW RECORD
CVE-2026-54166
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.1
HIGH
VIEW RECORD
CVE-2026-90445
Product identification pending
Reporter: ICS-CERT
7.1
HIGH
VIEW RECORD
CVE-2026-90447
Product identification pending
Reporter: ICS-CERT
7.1
HIGH
VIEW RECORD
CVE-2026-90448
Product identification pending
Reporter: ICS-CERT
7.1
HIGH
VIEW RECORD
CVE-2026-85083
Product identification pending
Reporter: ICS-CERT
7
HIGH
VIEW RECORD
CVE-2026-89242
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-89248
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-89261
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-89263
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-48490
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
6.9
MEDIUM
VIEW RECORD
CVE-2026-50025
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
6.9
MEDIUM
VIEW RECORD
CVE-2026-45056
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
6.9
MEDIUM
VIEW RECORD
CVE-2026-90449
Product identification pending
Reporter: ICS-CERT
6.9
MEDIUM
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.