Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 | |
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output. | |
| Title | Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-28T13:03:21.752Z
Reserved: 2026-08-06T13:04:28.162Z
Link: CVE-2026-19092
Updated: 2026-08-28T12:58:46.879Z
Status : Deferred
Published: 2026-08-27T20:17:04.150
Modified: 2026-08-28T18:43:25.883
Link: CVE-2026-19092
No data.
OpenCVE Enrichment
Updated: 2026-08-28T17:30:08Z