Authentication Bypass in Tutor LMS Plugin for WordPress
CVE-2026-12274
Key Information:
Badges
What is CVE-2026-12274?
The Tutor LMS plugin for WordPress prior to version 3.9.13 is vulnerable due to a failure to adequately verify user permissions when saving content. This oversight allows authenticated users with instructor-level access to overwrite any post or page, disregarding the ownership of the content. Thus, an attacker could exploit this weakness to modify or take control of posts even those managed by administrators, posing a significant risk to the integrity and security of the site's content.
Affected Version(s)
Tutor LMS 0 < 3.9.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved