---
id: CVE-2026-19093
title: >-
  The Tutor LMS  WordPress plugin before 4.0.6 does not validate a stored file
  path before using it to stream media, allowing users with the instructor role
  to read arbitrary files on the server, including files outside the web root.


  The …
summary: >-
  The Tutor LMS  WordPress plugin before 4.0.6 does not validate a stored file
  path before using it to stream media, allowing users with the instructor role
  to read arbitrary files on the server, including files outside the web root.


  The …
severity: none
published: '2026-08-22'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19093'
references:
  - url: 'https://wpscan.com/vulnerability/9f8361a9-d424-4346-9d92-6f27ab9261c9/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00459
epssPercentile: 0.37087
ingestedAt: '2026-08-23T04:42:13.028Z'
---

## Overview

The Tutor LMS  WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root.

The readable files include the WordPress configuration file, which exposes the database credentials and the authentication keys and salts, so authentication cookies can be forged.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
