30,000 WordPress Sites Affected by Authentication Bypass Vulnerability in Tutor LMS Pro WordPress Plugin

Date:

WP Vulnerability Notice

A serious security issue has been discovered in Tutor LMS Pro, a popular WordPress plugin with over 30,000 installations. This vulnerability allows attackers to access any user account, including admin accounts, if they know the associated email address. The risk level is high, as it could lead to unauthorized control of websites.

The issue was reported by researcher Phat RiO, who received a reward of $1,502 for their findings. Wordfence has already provided protection through a firewall rule, with updates rolled out on January 15, 2026, for premium users and on February 14, 2026, for free users.

To stay secure, it’s crucial for all Tutor LMS Pro users to update to the latest version, 3.9.6, which contains a fix for this vulnerability.

What This Means

This issue may affect your WordPress website if you are using the mentioned plugin or theme. Immediate action is recommended to avoid security risks.

How to Fix

  • Install the latest version of the affected plugin
  • Deactivate and remove unused plugins
  • Scan your website for malware
  • Ensure WordPress is up to date

Risk Level

This vulnerability could allow attackers to exploit your site.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...