Tutor LMS: 100,000+ sites at risk of takeover, update to 4.0.8
Published · Disclosed September 17, 2026 · Reviewed by Adam Taylor
| Plugin | Vulnerable | Fixed in |
|---|---|---|
| Tutor LMS – eLearning and online course solution | <= 4.0.7 | 4.0.8 |
Wordfence has disclosed a serious flaw in Tutor LMS, the course plugin used on more than 100,000 WordPress sites. It’s rated 8.8 out of 10 for severity, and it was fixed in version 4.0.8.
Am I affected?
You’re affected if your site runs Tutor LMS 4.0.7 or earlier.
Check under Plugins in your dashboard, where the version number sits under the plugin name.
The risk is higher if anyone can register on your site, which is normal for a course site selling to the public. Student accounts, free trial sign-ups, and open registration all count.
What it lets an attacker do
In plain terms: someone with the lowest-level account on your site, an ordinary student or subscriber, can run their own code on your server.
That’s about as bad as it gets. Once someone can run code, they can add admin accounts, plant backdoors, redirect visitors, mail spam from your domain, or read anything in your database, including student details and order records.
The technical name is PHP object injection. The plugin stored data in a form that WordPress later rebuilt into live code objects, and an attacker who controls that data controls what gets built. If registration is open on your site, the attacker doesn’t even need an existing account: they just sign up first.
What to do
- Update Tutor LMS to 4.0.8 now. Plugins → Update. This is the fix.
- If you can’t update immediately, close registration (Settings → General → untick “Anyone can register”) as a stopgap. It narrows the attack, but it isn’t a substitute for the update.
- After updating, check your user list under Users, sorted by registration date, for administrator accounts you don’t recognize.
- If anything looks off, don’t just delete the account. Attackers usually leave a hidden file that recreates access. Get the site checked properly.
There’s no public evidence of attacks yet, but that’s normal for the first days after a disclosure. Once the details are published, unpatched sites get scanned automatically, and course sites are attractive because they hold names, emails, and payment history.
On a Protect plan? Plugin updates are part of what we do, so this one is covered.