目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-78175— Tutor LMS 4.0.7 远程代码执行漏洞

一分钟漏洞结论

影响对象
themeum Tutor LMS – eLearning and online course solution
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WordPress 插件 Tutor LMS – eLearning 和在线课程解决方案在所有版本(包括 4.0.7 及之前)中均存在 PHP 对象注入(PHP Object Injection) 漏洞。该漏洞可通过 AJAX 处理程序中的 参数被触发。 根本原因在于: 该处理程序缺乏任何权限(capability)或角色检查,仅依赖 nonce 验证; 攻击者提供的输入经过 函数处理,该函数会将每个 字符替换为一个 66 字节的 HMAC 占位符标记,随后数据被序列化并通过 存储; 当元数据(meta)后续被读取

CVSS 8.8 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-78175 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution
来源: CVE Program / CVE List V5
Vulnerability Description
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sql()`, which replaces every `%` character with a 66-byte HMAC placeholder token before the data is serialized and stored via `update_user_meta()`; when the meta is later retrieved, the placeholder is collapsed back to a single `%`, leaving serialized string length declarations 65 bytes greater than the actual content, and because array keys originate from entirely unescaped POST field names, `unserialize()` over-reads into attacker-controlled bytes, allowing injection of an arbitrary serialized object stream. This makes it possible for authenticated attackers, with subscriber-level access and above, to achieve remote code execution on the server by triggering the `GuzzleHttp\Cookie\FileCookieJar` POP chain, reachable via the `spl_autoload_register` loader in `TUTOR\RestAPI` which loads the plugin's own bundled PayPal Composer autoloader, writing attacker-controlled content to an attacker-specified filename. This has an unauthenticated pathway when user registration is enabled, which is common for students and teachers to register, and it requires the monetization feature to be enabled.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
themeum Tutor LMS – eLearning and online course solution 0 ~ 4.0.7 -

二、漏洞 CVE-2026-78175 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-78175 的情报信息

登录查看更多情报信息。

CVE-2026-78175 补丁与修复 (5)

CVE-2026-78175 厂商安全公告 (1)

CVE-2026-78175 厂商页面 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-78175

暂无评论


发表评论