Beveiligingsadvies

CVE-2026-19092

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 17:05:37
Laatst bijgewerkt 2026-08-28 13:03:21
Toegewezen door WPScan
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.