LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-12275

Published
CVSS7.1
Severityhigh
Weakness
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-12275

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12275.