PT-2026-57637 · WordPress · Tutor Lms
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tutor LMS WordPress plugin versions prior to 3.9.13
Description
In the Droip and Kirki page-builder integration, the plugin fails to perform necessary enrollment, purchase, and private-course capability checks that are otherwise enforced in the core course handler. This allows authenticated users with subscriber-level access to enroll in paid or private courses without authorization, access private course content, and mark arbitrary courses as completed on sites where the Droip or Kirki integration is active.
Recommendations
Update Tutor LMS WordPress plugin to version 3.9.13 or later.
As a temporary mitigation, disable the Droip or Kirki page-builder integration.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tutor Lms