CVE-2026-0953Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. This is due to the plugin failing to verify that the email provided in the authentication request matches the email from the validated OAuth token. This makes it possible for unauthenticated attackers to log in as any existing user, including administrators, by supplying a valid OAuth token from their own account along with the victim's email address.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-10); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-10: 5Mentions · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-10: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-10: 5Technical Details · 2026-03-24: 103-1003-24
Signal classification4 categories
Disclosure
350.0%
Active Exploitation
116.7%
PoC
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-105
Active Exploitation1Disclosure3PoC1
2026-03-241
Patch1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    A critical 9.8 CVSS authentication bypass (CVE-2026-0953) in Tutor LMS Pro is being actively exploited in the wild. Update to version 3.9.6 immediately #TutorLMSPro #CVE20260953 #WordPressSecurity #CyberSecurity #InfoSec #Vulnerability #ActiveExploitation https://securityonline.info/under-active-attack-critical-9-8-cvss-tutor-lms-pro-flaw-exploited-in-the-wild-for-full-site-takeover/

    Post summary

    CVE-2026-0953 is a critical authentication bypass in Tutor LMS Pro, actively exploited in the wild; users are urged to update to version 3.9.6.

    03022314
    10.6K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    #WordPress Security Alert: CVE-2026-0953 https://nvd.nist.gov/vuln/detail/CVE-2026-0953 Is a serious WordPress risk in Tutor LMS Pro <= 3.9.5. A flaw in the Social Login addon can let attackers sign in as any existing user, even an admin, by mixing their own valid OAuth token with a victim’s email. Patch immediately. #WebSecurity #OAuth #WebsiteSecurity #SilentRisk #CVE #Malware

    Post summary

    WordPress Tutor LMS Pro <= 3.9.5 is vulnerable to an authentication bypass due to a Social Login flaw; users are urged to apply a patch immediately.

    1000036
    38 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0953 Authentication Bypass in Tutor LMS Pro WordPress Plugin via Social Login Addon https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0953

    Post summary

    A new authentication bypass vulnerability (CVE-2026-0953) has been identified in the Tutor LMS Pro WordPress plugin's Social Login Addon, but no further exploitation details or mitigations are provided.

    0001063
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-0953: CRITICAL] Vulnerable Tutor LMS Pro plugin for WordPress allows authentication bypass up to version 3.9.5 via Social Login addon due to lack of email verification, enabling possible attacker login.#cve,CVE-2026-0953,#cybersecurity https://cvefind.com/CVE-2026-0953

    Post summary

    The tweet announces a critical authentication bypass vulnerability in Tutor LMS Pro plugin for WordPress, affecting versions up to 3.9.5 via the Social Login addon.

    0000036
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0953 The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. This is due to the… https://www.cve.org/CVERecord?id=CVE-2026-0953

    Post summary

    The post announces an authentication bypass vulnerability (CVE‑2026‑0953) in Tutor LMS Pro plugin versions up to 3.9.5, triggered by the Social Login addon.

    00000146
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-0953: Tutor LMS Pro &lt;= 3.9.5 - Authenti... OAuth token + victim email = instant admin takeover on 50K+ WordPress LMS installs - trivial exploit, zero interaction r... https://zerodaysignal.com/vulnerability/CVE-2026-0953 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-0953 targets Tutor LMS Pro versions up to 3.9.5, enabling instant admin takeover with an OAuth token and victim email. The exploit is described as trivial and zero‑interaction, and a link to further details is provided.

    0000086
    142 followersView on X

Explore more