PT-2026-24178 · WordPress · Tutor Lms Pro+1

Phat Rio

·

Published

2026-03-10

·

Updated

2026-03-24

·

CVE-2026-0953

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tutor LMS Pro plugin for WordPress versions through 3.9.5
Description The Tutor LMS Pro plugin for WordPress is susceptible to authentication bypass through the Social Login addon. The plugin does not properly validate that the email address provided during authentication matches the email address associated with the validated OAuth token. This allows attackers to log in as any user, including administrators, by using a valid OAuth token from their own account and the email address of a target user. It is reported that this issue is being actively exploited in the wild. Approximately 50,000 WordPress LMS installations are potentially affected. The attack involves using a valid OAuth token along with a victim's email address to gain unauthorized access.
Recommendations Update to version 3.9.6 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-0953

Affected Products

Social Login
Tutor Lms Pro