THREATOPS
THREAT OPSThreat News › 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

medwordfencePublished 2026-09-17

<p>On August 23rd, 2026, <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/7733" rel="noopener noreferrer" target="_blank">Wordfence Argus</a>, our AI research agent specializing in complex vulnerability chains, discovered a PHP Object Injection vulnerability in Tutor LMS, a WordPress e-learning plugin active on more than 100,000 websites. This vulnerability allows any

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/09/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms/