SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12275

HIGH · CVSS 7.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The Tutor LMS WordPress plugin prior to version 3.9.13 is vulnerable due to insufficient capability checks in its Droip and Kirki page-builder integrations, allowing authenticated users with subscriber-level access to enroll in paid or private courses, access restricted content, and mark courses as completed without proper authorization. This vulnerability poses a significant risk to site integrity and content confidentiality, particularly for educational platforms utilizing these integrations. WordPress site administrators using the affected plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-12275
Severity
HIGH
CVSS
7.1
EPSS
0.17%
WordPress

Original NVD Description

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.