WordPress Plugins A.I CyberSecurity Scoring
WordPress Plugins
Company Information
Website:http://blog.ftwr.co.uk/wordpress/
Employees number:1
Number of followers:74
NAICS:5112
Industry Type:Software Development
Homepage:ftwr.co.uk
WordPress Plugins Risk Score (AI oriented)
Between 700 and 749
WordPress PluginsSoftware Development
Updated:
18/09/2026
18/09/2026
748/1000
Moderate
Ba
WordPress Plugins Global Score (TPRM)
xxxx
WordPress PluginsSoftware Development
Score locked

WordPress PluginsModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
748
AUGUST 2026
750
Vulnerability
23 Aug 2026 • WordPress Plugins
WordPress Site Owners: Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
High-Severity RCE Vulnerability in Tutor LMS Exposes 100,000+ WordPress Sites
747
CRITICAL-3
WOR1789727048
High-Severity RCE Vulnerability in Tutor LMS Exposes 100,000+ WordPress Sites
A critical remote code execution (RCE) vulnerability in the Tutor LMS plugin used by over 100,000 WordPress sites for e-learning and course management was discovered on August 23, 2026, by Wordfence Argus, an AI-assisted vulnerability research tool. The flaw, tracked as CVE-2026-78175 (CVSS 8.8), allows authenticated attackers with subscriber-level access to execute arbitrary code on vulnerable servers.
### Vulnerability Details
The issue stems from an authenticated PHP object injection chain in the plugin’s withdrawal-account management workflow, specifically the `tutor_save_withdraw_account` AJAX handler. While the endpoint required a valid frontend nonce, it lacked proper role or capability checks, enabling any logged-in user including those with minimal privileges to exploit it.
The attack leverages a serialization-length mismatch caused by improper use of WordPress’s `esc_sql()` function on user-submitted withdrawal form data. When processed, the function replaces percent characters with placeholders, inflating the serialized string’s declared length. Upon unserialization, PHP reads beyond the expected boundary, allowing attackers to inject malicious objects.
A viable property-oriented programming (POP) chain was identified, involving Tutor LMS’s PayPal Composer autoloader and Guzzle’s FileCookieJar class. In a successful exploit, an attacker could write a PHP payload to a web-accessible directory (e.g., `wp-content/uploads`) and execute OS commands under the web server’s privileges.
### Impact & Exploitation Conditions
- Affected Versions: Tutor LMS 4.0.7 and earlier
- Fixed Version: 4.0.8 (released September 10, 2026)
- Required Access: Subscriber-level account (or higher)
- Additional Risk: Many Tutor LMS deployments allow open student registration, lowering the barrier for unauthenticated attackers.
Exploitation could occur via:
- A malicious withdrawal request storing corrupted metadata.
- A second request triggering unserialization of the payload.
- Dashboard interactions (e.g., account settings or withdrawal pages).
### Mitigation & Response
Themeum, the plugin’s developer, patched the flaw in version 4.0.8 by:
- Adding an instructor-role check to the vulnerable endpoint.
- Removing unsafe `esc_sql()` processing.
- Validating withdrawal methods and restricting fields to a trusted whitelist.
Wordfence released a firewall rule on August 25 for Premium, Care, and Response customers, with free users receiving protection on September 24. While the rule provides temporary mitigation, patching remains critical.
### Recommended Actions for Site Owners
- Upgrade immediately to Tutor LMS 4.0.8 or later.
- Review public registration settings to limit unauthorized account creation.
- Audit subscriber accounts and user metadata for suspicious activity.
- Inspect web server logs for unusual AJAX requests targeting `tutor_save_withdraw_account`.
- Check `wp-content/uploads` for unexpected files that may indicate compromise.
The vulnerability underscores the risks of improper input handling and privilege escalation in widely used WordPress plugins, particularly in environments with open registration.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JULY 2026
750
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WordPress Plugins ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in August 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in July 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in June 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in May 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in April 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in March 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in February 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in January 2026 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in December 2025 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in November 2025 ??
What was WordPress Plugins's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on WordPress Plugins's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WordPress Plugins ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WordPress Plugins's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?