Skip to content

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

On August 23rd, 2026, Wordfence Argus, our AI research agent specializing in complex vulnerability chains, discovered a PHP Object Injection vulnerability in Tutor LMS, a WordPress e-learning plugin active on more than 100,000 websites. This vulnerability allows any authenticated attacker with subscriber-level access to achieve remote code execution on the server by exploiting an interaction between WordPress’s database abstraction layer and PHP’s serialization engine. Because Tutor LMS is built around student enrollment and most installations enable open registration by default, the authentication bar is effectively low for any visitor who can reach the site.

Our mission is to secure WordPress through defense in depth, which is why we are investing in proactive vulnerability research of this kind alongside our Bug Bounty Program. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to our multi-layered approach to security.