30,000 WordPress Sites Affected by Authentication Bypass Vulnerability in Tutor LMS Pro WordPress Plugin

Date:

WP Vulnerability Notice

A serious security issue has been discovered in Tutor LMS Pro, a popular WordPress plugin with over 30,000 installations. This vulnerability allows attackers to access any user account, including admin accounts, if they know the associated email address. The risk level is high, as it could lead to unauthorized control of websites.

The issue was reported by researcher Phat RiO, who received a reward of $1,502 for their findings. Wordfence has already provided protection through a firewall rule, with updates rolled out on January 15, 2026, for premium users and on February 14, 2026, for free users.

To stay secure, it’s crucial for all Tutor LMS Pro users to update to the latest version, 3.9.6, which contains a fix for this vulnerability.

What This Means

This issue may affect your WordPress website if you are using the mentioned plugin or theme. Immediate action is recommended to avoid security risks.

How to Fix

  • Install the latest version of the affected plugin
  • Deactivate and remove unused plugins
  • Scan your website for malware
  • Ensure WordPress is up to date

Risk Level

This vulnerability could allow attackers to exploit your site.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...