CVE-2026-12271: Unknown Tutor Lms
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.
Affected products
- Unknown Tutor Lms: before 3.9.13 (fixed in 3.9.13)
Published 2026-07-13. Last modified 2026-07-13.