CVE-2026-16759: Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters

Published Aug 28, 2026
·
Updated

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutorcoursefilterajax AJAX action. This is due to missing authorization on the handler combined with unsanitized array keys being passed to extract() inside tutorloadtemplate(), allowing attacker-controlled POST data to overwrite the local $template variable and, in the resulting templates/single-content-loader.php template, the $methodmap and $context variables invoked at $methodmap$context. This makes it possible for unauthenticated attackers to call an arbitrary zero-argument PHP function server-side and, via WordPress core edituser(), to create a persistent subscriber-level account from request parameters.

Affected Software

1 affected component
Tutor LMS Tutor LMS – eLearning and online course solution (WordPress plugin)<=4.0.5

Event History

Aug 28, 2026
CVE Published
via MITRE·03:39 AM
Data Sourced
via MITRE·03:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated remote attacker can exploit the affected AJAX action. No existing WordPress or Tutor LMS account is required.

2

What is the practical impact of exploitation?

An attacker can invoke arbitrary zero-argument PHP functions on the server. The described impact includes using WordPress core edit_user() with request parameters to create a persistent subscriber-level account.

3

Which deployments are affected?

Tutor LMS versions up to and including 4.0.5 are affected. The vulnerable path is the tutor_course_filter_ajax AJAX action and does not require authorization.

4

What conditions are required for exploitation?

The attacker needs network access to reach the WordPress site and submit POST parameters to the vulnerable AJAX action. The supplied data identifies no requirement for user interaction, credentials, or a complex attack setup.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203