SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12271

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The Tutor LMS WordPress plugin prior to version 3.9.13 is vulnerable, allowing authenticated users with subscriber-level access and higher to manipulate and force-complete other students' quiz attempts without proper ownership verification. This can lead to unauthorized changes in recorded marks and pass/fail results, compromising the integrity of the assessment process. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-12271
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress

Original NVD Description

The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.