CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12275

highCVSS 7.1covered by 1 sourcefirst seen 2026-07-13
The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.

⚡ Watch CVE-2026-12275

Get an email if CVE-2026-12275 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-12275

CVE.org record

Embed the live status

CVE-2026-12275 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12275 status](https://www.csirts.com/badge/CVE-2026-12275)](https://www.csirts.com/cve/CVE-2026-12275)