๐Ÿ” CVE Alert

CVE-2026-19093

UNKNOWN 0.0

Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The readable files include the WordPress configuration file, which exposes the database credentials and the authentication keys and salts, so authentication cookies can be forged.

Vendor unknown
Product tutor lms
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for unknown tutor lms

Be the first to know when new unknown vulnerabilities affecting unknown tutor lms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Tutor LMS
0 < 4.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/9f8361a9-d424-4346-9d92-6f27ab9261c9/

Credits

Sai Praneeth Koti WPScan