CVE-2026-19093Disclosure

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The readable files include the WordPress configuration file, which exposes the database credentials and the authentication keys and salts, so authentication cookies can be forged.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-22); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-22: 1Mentions · 2026-08-24: 1Technical Details · 2026-08-22: 108-2208-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    El plugin Tutor LMS para WordPress, utilizado por miles de sitios de e-learning en todo el mundo, presenta una vulnerabilidad catalogada como CVE-2026-19093 que permite a usuarios con rol de instructor acceder

    Post summary

    The post announces that the Tutor LMS WordPress plugin has a newly identified vulnerability (CVE‑2026‑19093) that permits instructors to access an unintended scope, but provides no additional technical or mitigation details.

    10000131
    22.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19093 The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arb… https://www.cve.org/CVERecord?id=CVE-2026-19093

    Post summary

    The text provides a brief disclosure of a file‑path validation flaw in Tutor LMS, but includes no PoC, exploitation code, patch details, or evidence of active exploitation.

    00000729
    58.0K followersView on X

Explore more