WordPress News: Two Plugin Updates You Can't Skip (Week of 22 September 2026)

This week's WordPress news comes down to two words: update now. A serious remote code execution flaw in a widely used e-learning plugin and a quieter, but still necessary, security release from WooCommerce both landed in the last few days. Neither is optional homework, and neither should wait until "this weekend."
Update Tutor LMS today if you run online courses
On September 17, Wordfence published research detailing a PHP object injection vulnerability in Tutor LMS, an e-learning plugin active on more than 100,000 WordPress sites. The flaw let an attacker with nothing more than a subscriber account, the same access level any new student gets the moment they register on your site, work their way up to full remote code execution on the server. That's about as bad as it gets: a low-privilege visitor turning into someone who can run their own code on your hosting.
Themeum, the company behind Tutor LMS, patched the issue in version 4.0.8 on September 10. Paying Wordfence customers received a firewall rule shielding them from known exploit attempts back in late August. If you run the free version of Wordfence, that same protection only arrives on September 24, which leaves a real gap for anyone who hasn't updated the plugin itself.
What this means for you: if you sell courses through Tutor LMS, check your plugin version right now. Anything older than 4.0.8 needs updating immediately, not on your next scheduled maintenance day. Because most course sites deliberately allow open student registration, the bar for an attacker to reach this bug is unusually low; they don't need a stolen password, just a sign-up form. Once you've updated, it's worth a quick read through our guide to WordPress security best practices if you haven't reviewed your setup in a while. As a certain wise old Jedi might say, these aren't droids you're looking for, but that plugin update absolutely is.
WooCommerce store owners: a small, sensible security patch
WooCommerce shipped version 11.1.1 on September 18, a dot release that tightens REST API authentication, cleans up permission checks on the legacy options API and mobile app login, and strengthens guest session validation. There's also a minor fix for Mini-Cart display styling when that block is hidden. WooCommerce has been upfront that the security issues addressed here are low risk and require privileged access to exploit, so this isn't a five-alarm story.
What this means for you: update anyway, and don't overthink it. There's no database migration involved, the fix is free, and "low risk requiring privileged access" has a habit of becoming "actively exploited" a few months down the line once attackers pick apart what changed. As with any store update, it's worth confirming you have a recent backup first, not because this particular release is risky, but because that's simply good practice every time you touch a live store that takes payments.
If your online store has grown well beyond a simple product catalogue, with custom pricing rules, complex logistics, or integrations WooCommerce was never quite built for, that's usually a sign you've outgrown off-the-shelf plugins rather than a sign something is wrong with WooCommerce itself. Plenty of businesses reach a point where a custom-built solution handles their specific workflow better than a general-purpose plugin stack ever could, and that's a conversation worth having once patch cycles start feeling like a full-time job.
The theme this week: small updates matter
Two stories, one lesson: even the "boring" updates matter, and the businesses that get hurt are almost always the ones running plugins two or three versions behind. A critical flaw in a course plugin and a quiet hardening release from an ecommerce platform both point the same direction: patch promptly, keep backups current, and don't assume "nothing has gone wrong yet" means nothing will.
If you'd rather not be the person manually checking plugin version numbers every week, that's exactly what a maintenance plan is for. It handles updates and monitoring automatically, so news like this week's doesn't have to become your emergency.
May the Code Be With You.
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


