CVE-2026-19092 CRITICAL

CVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing

Vendor Unknown
Product Tutor LMS
Published August 27, 2026
Last update August 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.

Explanation of Vulnerability in Simple Terms

02Summary

Tutor LMS versions 2.1.3 through 4.0.6 contain a critical vulnerability allowing unauthenticated attackers to read sensitive data, modify site content, and disrupt service. The flaw requires no user interaction and can be exploited remotely over the network. Update to version 4.0.6 or later immediately.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, and disrupt the site without logging in.

Potential impact on your site

04Site Impact

Your site's data, content, and availability are at immediate risk from remote attackers.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated