{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3athemeumtutor_lmswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-78175"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Tutor LMS (\u003c= 4.0.7)"],"_cs_severities":["high"],"_cs_tags":["wordpress","rce","php-injection","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Themeum"],"content_html":"\u003cp\u003eTutor LMS, a popular eLearning solution for WordPress, contains a critical vulnerability (CVE-2026-78175) affecting all versions up to and including 4.0.7. The vulnerability exists within the 'tutor_save_withdraw_account' AJAX handler, which fails to perform necessary capability or role checks. While the handler relies on a nonce, it incorrectly processes the 'withdraw_method_field' parameter by passing user-supplied input through 'esc_sql()'. This function introduces HMAC placeholders that, upon storage and subsequent retrieval, cause a discrepancy in serialized string length declarations. By providing crafted POST data, an attacker can trigger an 'unserialize()' operation on malformed data, leading to object injection. This permits the execution of a POP chain using 'GuzzleHttp\\Cookie\\FileCookieJar', effectively allowing an attacker to achieve remote code execution by writing arbitrary content to a file. The vulnerability is accessible to authenticated users with subscriber-level access and can be exploited by unauthenticated attackers if site registration is enabled and the monetization feature is active.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running Tutor LMS \u0026lt;= 4.0.7 with monetization features enabled.\u003c/li\u003e\n\u003cli\u003eAttacker registers as a student or teacher if user registration is enabled, or uses existing low-privileged credentials.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing a serialized PHP object designed to utilize the 'GuzzleHttp\\Cookie\\FileCookieJar' POP chain.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP POST request to the 'wp-admin/admin-ajax.php' endpoint with the 'action' set to 'tutor_save_withdraw_account'.\u003c/li\u003e\n\u003cli\u003eThe server-side code processes the 'withdraw_method_field' parameter, triggering the length discrepancy issue during the 'update_user_meta' operation.\u003c/li\u003e\n\u003cli\u003eUpon metadata retrieval, the application calls 'unserialize()' on the malformed input.\u003c/li\u003e\n\u003cli\u003eThe deserialization process executes the POP chain, resulting in arbitrary file write capabilities.\u003c/li\u003e\n\u003cli\u003eAttacker writes a PHP webshell to a publicly accessible directory to achieve remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated or low-privileged attackers to achieve remote code execution on the WordPress host. This grants full control over the web application, facilitating data exfiltration, defacement, or lateral movement within the hosting environment. Thousands of WordPress installations utilizing this eLearning plugin are potentially affected if the monetization feature is configured.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate Tutor LMS to version 4.0.8 or later immediately to apply the patch for CVE-2026-78175.\u003c/li\u003e\n\u003cli\u003eDisable public user registration on WordPress sites if not strictly necessary until the update is applied.\u003c/li\u003e\n\u003cli\u003eTemporarily disable the monetization feature in Tutor LMS to mitigate the attack vector.\u003c/li\u003e\n\u003cli\u003eReview server logs for anomalous POST requests to 'admin-ajax.php' containing highly encoded or serialized-looking strings.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-12T09:19:07Z","date_published":"2026-09-12T09:19:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tutor-lms-rce/","summary":"Tutor LMS plugin versions up to 4.0.7 are vulnerable to remote code execution via PHP object injection in the tutor_save_withdraw_account AJAX handler, allowing attackers to leverage POP chains.","title":"PHP Object Injection in Tutor LMS Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-tutor-lms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}