CVE-2026-78175 | meum Tutor LMS up to 4.0.7 on WordPress Ajax TUTORRestAPI.tutor_save_withdraw_account withdraw_method_field deserialization
A vulnerability was found in meum Tutor LMS up to 4.0.7 on WordPress and classified as critical. This affects the function TUTORRestAPI.tutor_save_withdraw_account of the component Ajax Handler. Such manipulation of the argument withdraw_method_field leads to deserialization.
This vulnerability is traded as CVE-2026-78175. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More