CVE-2026-19092

Summary

The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.

Affected Software

VendorProductVersion RangeStatus
UnknownTutor LMS2.1.3 < 4.0.6affected

Weaknesses

  • CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

References