CVE-2026-19093: The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allow
infovulnerability
security
Summary
The Tutor LMS WordPress plugin before version 4.0.6 has a security flaw where it doesn't check file paths before using them to stream media files, allowing instructors to read any file on the server, including sensitive files like the WordPress configuration file that contains database passwords and authentication keys (secret codes used to verify user sessions).
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
August 22, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19093
First tracked: August 22, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%