CRITICAL 9.8 CVE-2026-19092 Published 27 Aug 2026

Tutor LMS WordPress Plugin PHP Injection Flaw

Worried this affects one of your servers?

The Tutor LMS WordPress plugin, before version 4.0.6, has a vulnerability that allows unauthenticated users to execute arbitrary zero-argument PHP functions by manipulating request data during template rendering.

This is due to the plugin not properly sanitizing user input, which can lead to PHP code injection.

Reference: CVE-2026-19092 on NVD

← Back to Security News