Tutor LMS Plugin Exposes WordPress Credentials Due to Route Validation Flaw
ID: 7fbfc003-985b-59bb-ae84-3804d4e8f48f
STIX ID: report--7fbfc003-985b-59bb-ae84-3804d4e8f48f
Feed Name: ThreatCluster
Threat Score
A critical vulnerability (CVE-2026-19093) in the Tutor LMS WordPress plugin permits instructors to access wp-config.php and other sensitive server files, exposing database credentials and authentication keys; thousands of e-learning sites are affected and administrators are urged to apply immediate mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
