PT-2026-79511 · WordPress · Tutor Lms
CVE-2026-19093
·
Published
2026-08-22
·
Updated
2026-08-23
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tutor LMS versions prior to 4.0.6
Description
The plugin fails to validate a stored file path used for streaming media. This allows users with the instructor role to perform an arbitrary file read on the server, including files located outside the web root. This issue can be used to access the WordPress configuration file, exposing database credentials, authentication keys, and salts, which may enable the forgery of authentication cookies.
Recommendations
Update Tutor LMS to version 4.0.6 or later.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tutor Lms