WordPress · Tutor Lms · CVE-2026-12275
**Name of the Vulnerable Software and Affected Versions**
Tutor LMS WordPress plugin versions prior to 3.9.13
**Description**
In the Droip and Kirki page-builder integration, the plugin fails to perform necessary enrollment, purchase, and private-course capability checks that are otherwise enforced in the core course handler. This allows authenticated users with subscriber-level access to enroll in paid or private courses without authorization, access private course content, and mark arbitrary courses as completed on sites where the Droip or Kirki integration is active.
**Recommendations**
Update Tutor LMS WordPress plugin to version 3.9.13 or later.
As a temporary mitigation, disable the Droip or Kirki page-builder integration.