← Back to feed
vendor Wordfence Blog

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

Wordfence Blog WordPress

Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could a...

T1190
Read the full story Wordfence Blog →

Related Coverage

vendor PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core Wordfence Blog · Sep 22 vendor Unmasking EvilTokens: Getting to the root of device code phishing Microsoft Security Blog · Sep 22 vendor Inside a Malicious, Stealthy WordPress Must Use Plugin Wordfence Blog · Sep 22