CVE

CVE-2026-12273 — Tutor LMS – eLearning and online course solution [tutor] < 3.9.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12273 Tutor LMS – eLearning and online course solution [tutor] < 3.9.13 Improper Access Control Unknown < 3.9.13 3.9.13 2026-06-22

CVE-2026-12273

The Tutor LMS plugin for WordPress, prior to version 3.9.13, contains a security flaw that enables certain users to create unmoderated comments with embedded links and HTML code. This vulnerability arises from inadequate validation of user input in one of the plugin's handlers, allowing authenticated subscribers or higher-level users to post pre-approved comments on any site content without going through the moderation queue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.