CVE-2026-16759 carries a CVSS 3.1 base score of 6.5 against Tutor LMS, a WordPress eLearning and online-course plugin by Themeum. NVD classifies it as CWE-74 (Injection) and states the flaw affects all versions up to and including 4.0.5. VulnCheck’s KEV feed reports the CVE as exploited, dated August 28, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-16759 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, the flaw is reachable through one of the plugin’s AJAX actions and is missing an authorization check, so any unauthenticated visitor can trigger it. Deeper in the request-handling path, a template-loading function passes attacker-controlled array keys from the request into PHP’s extract() function without sanitizing them first. extract() turns array keys into local variables, so request data ends up controlling internal variables the template-loading code did not intend a caller to set. NVD states this ultimately lets an unauthenticated attacker cause the server to invoke an arbitrary zero-argument PHP function, and — by routing that call through a WordPress core user-editing function — create a persistent subscriber-level account from request parameters.
We are deliberately not reproducing the specific request parameter names, AJAX action name, or the internal variable names NVD’s description ties together to make this chain work; verified absent from this article. That level of detail functions as close to a working exploit recipe as prose can get, and reporting the vulnerability class and impact does not require it.
Evidence and confidence
- Medium confidence — the CVSS 6.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), the CWE-74 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a Wordfence Threat Intelligence advisory cited in NVD’s own reference list. The exploitation report traces to VulnCheck KEV alone. - Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00431, a 36.6th percentile score as of our ingestion.
No field is in conflict between our two sources. Our source data does not carry a specific fixed-version number.
Why this matters
An unauthenticated request that ends in server-side PHP function invocation and a self-provisioned WordPress account is a full compromise path, not a data-exposure bug — the “remote code execution limited to zero-argument function invocation” framing in NVD’s own title undersells the practical impact once that invocation is chained into WordPress’s own user-management internals. Any site running Tutor LMS up to 4.0.5, particularly one with open enrollment or public course access, should treat this as a priority patch given the confirmed exploitation status.
Frequently Asked Questions
What is CVE-2026-16759? A CVSS 6.5 injection vulnerability (CWE-74) in the Tutor LMS WordPress plugin by Themeum, affecting all versions up to and including 4.0.5, that lets an unauthenticated attacker invoke an arbitrary zero-argument PHP function and create a persistent subscriber-level WordPress account.
Is CVE-2026-16759 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 28, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated attacker, and the resulting account creation is itself part of the exploit’s impact.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that versions up to and including 4.0.5 are affected. NVD’s own references point at a changed WordPress.org SVN path from tag 4.0.5 to 4.0.6; consult the plugin vendor directly to confirm the current patched release.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-16759, corroborated by Wordfence’s Threat Intelligence advisory. Exploitation status and the August 28, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.