100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
A high-severity security advisory was published regarding Tutor LMS.
Tracked as CVE-2026-78175 with a CVSS severity score of N/A/10.
Executive Threat Summary
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.
The post 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS appeared first on Wordfence.
This security vulnerability presents a direct risk of unauthorized data access, arbitrary script injection, or remote site compromise if left unaddressed. Because threat actors scan the internet automatically within hours of vulnerability disclosures, affected sites must be audited immediately.
Action Plan for Website Owners
- Check Your Installed Version: Verify what version of Tutor LMS is running in your WordPress admin dashboard (Plugins → Installed Plugins).
- Apply Patches Immediately: If a newer release is available, backup your database and update the software without delay.
- Inspect for Indicators of Attack: If your site cannot be updated immediately, check for unexpected administrative accounts or unusual traffic spikes.
- Get an Infrastructure Audit: Submit a rescue or security inquiry with Delvok. We verify server integrity and migrate your site to an isolated container environment.