CVE-2026-0953
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0953 is a critical authentication bypass vulnerability in the Tutor LMS Pro plugin for WordPress, affecting all versions up to and including 3.9.5 via the Social Login addon. The flaw allows unauthenticated attackers to log in as any existing user — including administrators — by supplying a valid OAuth token from their own account paired with a victim's email address, without the plugin verifying that the email matches the token. It was published on March 10, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, ENISA EUVD).

Technical details

The root cause is classified as CWE-287 (Improper Authentication): the Social Login addon fails to validate that the email address submitted in an authentication request corresponds to the email associated with the presented OAuth token. An attacker can obtain a legitimate OAuth token by authenticating with their own social account, then replay that token alongside any victim's email address to hijack that account's session. No special privileges or user interaction are required, and the attack is conducted entirely over the network with low complexity. This design flaw effectively decouples token validation from identity verification, making account impersonation trivial (Wordfence, Infinitsec).

Impact

Successful exploitation grants an unauthenticated attacker full access to any WordPress account on the affected site, including administrator accounts, resulting in complete confidentiality, integrity, and availability compromise. Attackers can exfiltrate sensitive user and site data, install malicious plugins or web shells, modify site content, create backdoor accounts, or take the site fully offline. Approximately 30,000 WordPress sites are estimated to be running the affected plugin, representing a broad attack surface (Malware News, SecurityOnline).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been confirmed, and no specific threat actor attribution has been made. However, SecurityOnline reported the vulnerability as being exploited in the wild for full site takeover (SecurityOnline). The EPSS score is approximately 0.04%, reflecting low automated exploitation probability at the time of scoring, though the trivial exploitation mechanics and high-value target profile elevate real-world risk. The vulnerability has been detected by Qualys (detection ID 531077) and is not currently listed in the CISA KEV catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running Tutor LMS Pro ≤ 3.9.5 with the Social Login addon enabled, using tools like WPScan, Shodan, or manual inspection of plugin metadata.
  2. Obtain a valid OAuth token: Register or log in to any social account (e.g., Google, Facebook) supported by the plugin's Social Login addon to obtain a valid OAuth token for the attacker's own account.
  3. Identify target account: Enumerate or guess the email address of a target user (e.g., an administrator) on the victim WordPress site, potentially via exposed user profiles, author pages, or contact information.
  4. Craft malicious authentication request: Submit an authentication request to the Social Login endpoint, supplying the attacker's valid OAuth token alongside the victim's email address instead of the attacker's own email.
  5. Bypass authentication: Because the plugin does not verify that the submitted email matches the OAuth token's associated email, the server authenticates the request and establishes a session as the victim user.
  6. Achieve full site compromise: With administrator-level access, install malicious plugins, create backdoor accounts, exfiltrate data, or deploy web shells for persistent access (Wordfence, Infinitsec).

Indicators of compromise

  • Logs: WordPress authentication logs showing successful logins via the Social Login addon from IP addresses not associated with the legitimate account owner; multiple login events for high-privilege accounts (e.g., admin) originating from unfamiliar geolocations or IPs in rapid succession.
  • Logs: Web server access logs with POST requests to the Tutor LMS Pro Social Login authentication endpoint containing mismatched email parameters relative to the OAuth provider's token.
  • File System: Newly installed or modified plugins not authorized by site administrators; presence of web shell files (e.g., .php files with obfuscated code) in the WordPress uploads or plugins directories.
  • WordPress Admin: Unexpected new administrator accounts created after the Social Login authentication events; changes to site settings, theme files, or plugin configurations without corresponding authorized activity.
  • Network: Outbound connections from the WordPress server to unknown external IPs following suspicious login events, potentially indicating data exfiltration or C2 communication (Wordfence).

Mitigation and workarounds

Users should immediately upgrade Tutor LMS Pro to a version newer than 3.9.5, which contains the fix for this authentication bypass (Tutor LMS Releases). If immediate patching is not feasible, disabling the Social Login addon within the plugin settings will eliminate the attack vector until the update can be applied. After patching, administrators should audit WordPress user accounts for unauthorized additions, review authentication logs for suspicious activity, and rotate credentials for any accounts that may have been compromised (Wordfence).

Community reactions

Wordfence, the CVE assigner, published a detailed vulnerability entry and included the flaw in their weekly WordPress vulnerability report for March 9–15, 2026 (Wordfence Weekly Report). SecurityOnline reported active in-the-wild exploitation for full site takeover, elevating community concern (SecurityOnline). The Hacker News included the vulnerability in their weekly recap covering notable security events (The Hacker News). Social media activity was observed on Bluesky and Mastodon/Infosec.exchange, with security researchers flagging the critical CVSS score and broad site impact.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management