Tutor LMS Remote Code Execution: What You Need to Know (CVE-2024-XXXX)
A critical security flaw has been disclosed in Tutor LMS, an e-learning and online course plugin active on more than 100,000 WordPress sites.
This vulnerability is categorized as Critical (CVSS 9.8/10) because it allows an attacker to achieve Remote Code Execution (RCE). This means an attacker can run arbitrary software commands on your server, access your database, or take complete control of the site.
Am I Vulnerable?
You are at risk if:
- Your site runs Tutor LMS or Tutor LMS Pro
- Your version is prior to the latest patched release
- Student or user registration is enabled on your site (which is standard for course platforms)
Because Tutor LMS sites are designed for student signups, an attacker does not need an administrator account. They can simply register for a free account, send a specially crafted request through an enrollment endpoint, and compromise the server.
What Should You Do Immediately?
- Update Immediately: Go to Plugins → Installed Plugins in your WordPress dashboard and update Tutor LMS to the latest version immediately.
- Review User Registrations: Check Users → All Users for any accounts created recently with odd usernames or temporary email domains.
- If You Suspect Infiltration: Contact Delvok for an emergency security scan. We verify server access logs for exploit attempts and ensure no webshells were planted.