CVE-2026-12275: Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration
The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12275?
CVE-2026-12275 has a severity rating of high with a CVSS score of 7.1.
How do I fix CVE-2026-12275?
To fix CVE-2026-12275, update the Tutor LMS WordPress plugin to version 3.9.13 or later.
What vulnerabilities are associated with CVE-2026-12275?
CVE-2026-12275 allows unauthorized course enrollment and potential disclosure of private course content for users with subscriber-level access.
Who is affected by CVE-2026-12275?
CVE-2026-12275 affects users of the Tutor LMS WordPress plugin versions prior to 3.9.13.
What are the potential impacts of CVE-2026-12275?
The potential impacts of CVE-2026-12275 include unauthorized access to paid or private courses, leading to content disclosure.