THREAT OPS › Threat News › 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
<p>On August 23rd, 2026, <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/7733" rel="noopener noreferrer" target="_blank">Wordfence Argus</a>, our AI research agent specializing in complex vulnerability chains, discovered a PHP Object Injection vulnerability in Tutor LMS, a WordPress e-learning plugin active on more than 100,000 websites. This vulnerability allows any
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 9bf72594e071c28445ed7a1be0de1a23md5
- f97767e14ecb84ebfb6efdeaad2ee129md5
- CVE-2026-78175cve
- https://www.cve.org/CVERecord?id=CVE-2026-78175url
- www.gravatar.comdomain