PT-2026-57637 · WordPress · Tutor Lms

·

CVE-2026-12275

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS WordPress plugin versions prior to 3.9.13
Description In the Droip and Kirki page-builder integration, the plugin fails to perform necessary enrollment, purchase, and private-course capability checks that are otherwise enforced in the core course handler. This allows authenticated users with subscriber-level access to enroll in paid or private courses without authorization, access private course content, and mark arbitrary courses as completed on sites where the Droip or Kirki integration is active.
Recommendations Update Tutor LMS WordPress plugin to version 3.9.13 or later. As a temporary mitigation, disable the Droip or Kirki page-builder integration.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-12275

Affected Products

Tutor Lms