CVE-2026-12274: Unknown Tutor Lms
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.
Affected products
- Unknown Tutor Lms: before 3.9.13 (fixed in 3.9.13)
Published 2026-07-13. Last modified 2026-07-13.