Quttera - eCommerce Security[verified]@MNovofastovskyPatch
WordPress Tutor LMS Pro <= 3.9.5 is vulnerable to an authentication bypass due to a Social Login flaw; users are urged to apply a patch immediately.
Gray Hats@the_yellow_fallActive Exploitation
CVE-2026-0953 is a critical authentication bypass in Tutor LMS Pro, actively exploited in the wild; users are urged to update to version 3.9.6.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new authentication bypass vulnerability (CVE-2026-0953) has been identified in the Tutor LMS Pro WordPress plugin's Social Login Addon, but no further exploitation details or mitigations are provided.
CVEFind.com@CveFindComDisclosure
The tweet announces a critical authentication bypass vulnerability in Tutor LMS Pro plugin for WordPress, affecting versions up to 3.9.5 via the Social Login addon.
CVE@CVEnewDisclosure
The post announces an authentication bypass vulnerability (CVE‑2026‑0953) in Tutor LMS Pro plugin versions up to 3.9.5, triggered by the Social Login addon.
0day Signal@0dayPublishingPoC
CVE-2026-0953 targets Tutor LMS Pro versions up to 3.9.5, enabling instant admin takeover with an OAuth token and victim email. The exploit is described as trivial and zero‑interaction, and a link to further details is provided.