Product
Tutor LMS plugin versions up to 4.0.7 are vulnerable to remote code execution via PHP object injection in the tutor_save_withdraw_account AJAX handler, allowing attackers to leverage POP chains.