CVE

CVE-2026-12275 — Tutor LMS – eLearning and online course solution [tutor] < 3.9.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12275 Tutor LMS – eLearning and online course solution [tutor] < 3.9.13 Improper Authentication Unknown < 3.9.13 3.9.13 2026-06-22

CVE-2026-12275

Authenticated users with basic permissions can bypass enrollment restrictions on certain courses if a site uses either the Droip or Kirki page-builder integrations with Tutor LMS versions prior to 3.9.13. This vulnerability arises from inconsistent access control checks in these integrations, allowing unauthorized course actions. As a result, affected sites may experience unapproved enrollments and tampering with course completion records.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.