WP Vulnerability Notice
A serious security issue has been discovered in Tutor LMS Pro, a popular WordPress plugin with over 30,000 installations. This vulnerability allows attackers to access any user account, including admin accounts, if they know the associated email address. The risk level is high, as it could lead to unauthorized control of websites.
The issue was reported by researcher Phat RiO, who received a reward of $1,502 for their findings. Wordfence has already provided protection through a firewall rule, with updates rolled out on January 15, 2026, for premium users and on February 14, 2026, for free users.
To stay secure, it’s crucial for all Tutor LMS Pro users to update to the latest version, 3.9.6, which contains a fix for this vulnerability.
What This Means
This issue may affect your WordPress website if you are using the mentioned plugin or theme. Immediate action is recommended to avoid security risks.
How to Fix
- Install the latest version of the affected plugin
- Deactivate and remove unused plugins
- Scan your website for malware
- Ensure WordPress is up to date
Risk Level
This vulnerability could allow attackers to exploit your site.
Source: View Original Report
