CVE-2026-19092
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, all
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 27, 2026 · Last modified: Aug 27, 2026
Not enough EPSS history yet.
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
No related CVEs by CWE or product.