SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19092

CRITICAL · CVSS 9.8 EPSS 1.50%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Tutor LMS WordPress plugin prior to version 4.0.6 is vulnerable to a critical security flaw that allows unauthenticated users to overwrite internal variables during template rendering, enabling the execution of arbitrary zero-argument PHP functions. This could lead to unauthorized access to sensitive information or system compromise. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-19092
Severity
CRITICAL
CVSS
9.8
EPSS
1.50%
WordPress

Original NVD Description

The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.