Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
WordPress Plugins

WordPress Plugins Vendor Cyber Rating & Cyber Score

ftwr.co.uk

WordPress plugin development


WordPress Plugins A.I CyberSecurity Scoring

WordPress Plugins
Company Information
Website:http://blog.ftwr.co.uk/wordpress/
Employees number:1
Number of followers:74
NAICS:5112
Industry Type:Software Development
Homepage:ftwr.co.uk
WordPress Plugins Risk Score (AI oriented)
Between 700 and 749
logo
WordPress PluginsSoftware Development
Updated:
18/09/2026
748/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
WordPress Plugins Global Score (TPRM)
xxxx
logo
WordPress PluginsSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

WordPress PluginsModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
748Before Incident
AUGUST 2026
750Before Incident
Vulnerability
23 Aug 2026WordPress Plugins
WordPress Site Owners: Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability

High-Severity RCE Vulnerability in Tutor LMS Exposes 100,000+ WordPress Sites

747After Incident
CRITICAL-3
WOR1789727048
High-Severity RCE Vulnerability in Tutor LMS Exposes 100,000+ WordPress Sites A critical remote code execution (RCE) vulnerability in the Tutor LMS plugin used by over 100,000 WordPress sites for e-learning and course management was discovered on August 23, 2026, by Wordfence Argus, an AI-assisted vulnerability research tool. The flaw, tracked as CVE-2026-78175 (CVSS 8.8), allows authenticated attackers with subscriber-level access to execute arbitrary code on vulnerable servers. ### Vulnerability Details The issue stems from an authenticated PHP object injection chain in the plugin’s withdrawal-account management workflow, specifically the `tutor_save_withdraw_account` AJAX handler. While the endpoint required a valid frontend nonce, it lacked proper role or capability checks, enabling any logged-in user including those with minimal privileges to exploit it. The attack leverages a serialization-length mismatch caused by improper use of WordPress’s `esc_sql()` function on user-submitted withdrawal form data. When processed, the function replaces percent characters with placeholders, inflating the serialized string’s declared length. Upon unserialization, PHP reads beyond the expected boundary, allowing attackers to inject malicious objects. A viable property-oriented programming (POP) chain was identified, involving Tutor LMS’s PayPal Composer autoloader and Guzzle’s FileCookieJar class. In a successful exploit, an attacker could write a PHP payload to a web-accessible directory (e.g., `wp-content/uploads`) and execute OS commands under the web server’s privileges. ### Impact & Exploitation Conditions - Affected Versions: Tutor LMS 4.0.7 and earlier - Fixed Version: 4.0.8 (released September 10, 2026) - Required Access: Subscriber-level account (or higher) - Additional Risk: Many Tutor LMS deployments allow open student registration, lowering the barrier for unauthenticated attackers. Exploitation could occur via: - A malicious withdrawal request storing corrupted metadata. - A second request triggering unserialization of the payload. - Dashboard interactions (e.g., account settings or withdrawal pages). ### Mitigation & Response Themeum, the plugin’s developer, patched the flaw in version 4.0.8 by: - Adding an instructor-role check to the vulnerable endpoint. - Removing unsafe `esc_sql()` processing. - Validating withdrawal methods and restricting fields to a trusted whitelist. Wordfence released a firewall rule on August 25 for Premium, Care, and Response customers, with free users receiving protection on September 24. While the rule provides temporary mitigation, patching remains critical. ### Recommended Actions for Site Owners - Upgrade immediately to Tutor LMS 4.0.8 or later. - Review public registration settings to limit unauthorized account creation. - Audit subscriber accounts and user metadata for suspicious activity. - Inspect web server logs for unusual AJAX requests targeting `tutor_save_withdraw_account`. - Check `wp-content/uploads` for unexpected files that may indicate compromise. The vulnerability underscores the risks of improper input handling and privilege escalation in widely used WordPress plugins, particularly in environments with open registration.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: 100,000+ WordPress sites using Tutor LMSOperational Impact: Potential unauthorized code execution on vulnerable serversBrand Reputation Impact: Potential reputational damage for affected sites
JULY 2026
750Before Incident
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for WordPress Plugins ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in August 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in July 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in June 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in May 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in April 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in March 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in February 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in January 2026 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in December 2025 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in November 2025 ?
?
What was WordPress Plugins's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on WordPress Plugins's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with WordPress Plugins ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view WordPress Plugins's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
WordPress Plugins Cyber Scoring History | Rankiteo