CVE-2026-12271: Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12271?
The severity of CVE-2026-12271 is rated as medium with a CVSS score of 5.4.
How do I fix CVE-2026-12271?
To fix CVE-2026-12271, update the Tutor LMS WordPress plugin to version 3.9.13 or later.
What type of vulnerability is CVE-2026-12271?
CVE-2026-12271 is an arbitrary quiz attempt modification vulnerability due to insufficient ownership verification.
Who is affected by CVE-2026-12271?
Authenticated users with subscriber-level access and above can be affected by CVE-2026-12271.
What can an attacker do with CVE-2026-12271?
An attacker can modify and force-complete other students' quiz attempts, potentially overwriting their recorded marks.