
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0953 is a critical authentication bypass vulnerability in the Tutor LMS Pro plugin for WordPress, affecting all versions up to and including 3.9.5 via the Social Login addon. The flaw allows unauthenticated attackers to log in as any existing user — including administrators — by supplying a valid OAuth token from their own account paired with a victim's email address, without the plugin verifying that the email matches the token. It was published on March 10, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, ENISA EUVD).
The root cause is classified as CWE-287 (Improper Authentication): the Social Login addon fails to validate that the email address submitted in an authentication request corresponds to the email associated with the presented OAuth token. An attacker can obtain a legitimate OAuth token by authenticating with their own social account, then replay that token alongside any victim's email address to hijack that account's session. No special privileges or user interaction are required, and the attack is conducted entirely over the network with low complexity. This design flaw effectively decouples token validation from identity verification, making account impersonation trivial (Wordfence, Infinitsec).
Successful exploitation grants an unauthenticated attacker full access to any WordPress account on the affected site, including administrator accounts, resulting in complete confidentiality, integrity, and availability compromise. Attackers can exfiltrate sensitive user and site data, install malicious plugins or web shells, modify site content, create backdoor accounts, or take the site fully offline. Approximately 30,000 WordPress sites are estimated to be running the affected plugin, representing a broad attack surface (Malware News, SecurityOnline).
As of the time of reporting, no public proof-of-concept exploit code has been confirmed, and no specific threat actor attribution has been made. However, SecurityOnline reported the vulnerability as being exploited in the wild for full site takeover (SecurityOnline). The EPSS score is approximately 0.04%, reflecting low automated exploitation probability at the time of scoring, though the trivial exploitation mechanics and high-value target profile elevate real-world risk. The vulnerability has been detected by Qualys (detection ID 531077) and is not currently listed in the CISA KEV catalog (Feedly).
.php files with obfuscated code) in the WordPress uploads or plugins directories.Users should immediately upgrade Tutor LMS Pro to a version newer than 3.9.5, which contains the fix for this authentication bypass (Tutor LMS Releases). If immediate patching is not feasible, disabling the Social Login addon within the plugin settings will eliminate the attack vector until the update can be applied. After patching, administrators should audit WordPress user accounts for unauthorized additions, review authentication logs for suspicious activity, and rotate credentials for any accounts that may have been compromised (Wordfence).
Wordfence, the CVE assigner, published a detailed vulnerability entry and included the flaw in their weekly WordPress vulnerability report for March 9–15, 2026 (Wordfence Weekly Report). SecurityOnline reported active in-the-wild exploitation for full site takeover, elevating community concern (SecurityOnline). The Hacker News included the vulnerability in their weekly recap covering notable security events (The Hacker News). Social media activity was observed on Bluesky and Mastodon/Infosec.exchange, with security researchers flagging the critical CVSS score and broad site impact.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."