>_
Delvok
← Back to Blog
Vulnerability Alert

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

September 30, 2026·Delvok Threat Intel·2 min read

A high-severity security advisory was published regarding Tutor LMS.
Tracked as CVE-2026-78175 with a CVSS severity score of N/A/10.

Executive Threat Summary

Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.
The post 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS appeared first on Wordfence.

This security vulnerability presents a direct risk of unauthorized data access, arbitrary script injection, or remote site compromise if left unaddressed. Because threat actors scan the internet automatically within hours of vulnerability disclosures, affected sites must be audited immediately.

Action Plan for Website Owners

  1. Check Your Installed Version: Verify what version of Tutor LMS is running in your WordPress admin dashboard (Plugins → Installed Plugins).
  2. Apply Patches Immediately: If a newer release is available, backup your database and update the software without delay.
  3. Inspect for Indicators of Attack: If your site cannot be updated immediately, check for unexpected administrative accounts or unusual traffic spikes.
  4. Get an Infrastructure Audit: Submit a rescue or security inquiry with Delvok. We verify server integrity and migrate your site to an isolated container environment.

What Delvok Does Differently

Every site we rescue is migrated to isolated container infrastructure — your own web root, database, and server process. 24/7 monitoring catches threats before they become problems. Forensic-grade remediation ensures nothing is left behind.

Get Protected