← Back to feed
vendor Wordfence Blog

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

Wordfence Blog WordPress

Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could a...

T1190
Read the full story Wordfence Blog →

Related Coverage

vendor Transforming Bedrock Guardrails events into OCSF with CloudWatch AWS Security Blog · Sep 21 vendor Python Workers are now generally available Cloudflare Blog · Sep 21 vendor Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server Wordfence Blog · Sep 18