Impact
Based on the description, the Tutor LMS plugin contains a PHP Object Injection flaw that allows an attacker to craft manipulated serialized data. The flaw occurs in the withdraw endpoint, where untrusted POST data is serialized and stored in user meta without proper validation, leading to deserialization of attacker‑supplied objects. Exploiting this weakness can result in remote code execution through the GuzzleHttp\\Cookie\\FileCookieJar chain loaded via spl_autoload_register. The vulnerability addresses CWE-502.
Affected Systems
The flaw affects the Tutor LMS – eLearning and online course solution plugin released by Themeum. All releases up to and including version 4.0.7 are impacted, while newer releases are presumed to contain a patch.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector requires an authenticated user with subscriber-level access or another role that can invoke the withdrawal AJAX endpoint. An unauthenticated attacker may achieve the same if user registration is enabled and the monetization feature is active. The vulnerability carries a CVSS score of 8.8, classifying it as high severity, and an EPSS score of < 1%, indicating a low likelihood of current exploitation. This CVE is not listed in the CISA KEV catalog. If the conditions are met, the attacker can trigger the malicious object chain via the withdrawal API and achieve remote code execution on the WordPress server.
OpenCVE Enrichment