Vulnerability Description
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The readable files include the WordPress configuration file, which exposes the database credentials and the authentication keys and salts, so authentication cookies can be forged.
References
FAQ
What is CVE-2026-19093?
CVE-2026-19093 is a documented vulnerability. The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, includ...
How severe is CVE-2026-19093?
CVSS scoring is not yet available for CVE-2026-19093. Check NVD for updates.
Is there a patch for CVE-2026-19093?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.