Impact
The Tutor LMS WordPress plugin, before version 3.9.13, fails to enforce its core course handler checks within the Droip and Kirki page‑builder integration. As a result, authenticated users with subscriber‑level access can enroll in paid or private courses, view private course materials, and mark courses as completed without authorization. This allows a privileged user to bypass course enrollment restrictions and gain unauthorized access to confidential content, compromising the confidentiality and integrity of protected learning material. This vulnerability involves improper authorization checks (CWE-285) and information disclosure (CWE-200).
Affected Systems
All installations of the Tutor LMS plugin on WordPress sites using Droip or Kirki integration and running a version earlier than 3.9.13 are affected.
Risk and Exploitability
The vulnerability requires an authenticated subscriber account, which is common on learning platforms, making the attack vector straightforward. Because the flaw allows course enrollment and content access control bypass, it can be leveraged for data leakage and unauthorized completion marking. The CVSS score of 7.1 indicates high severity, while the EPSS score of <1% indicates that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, but the lack of core checks provides a clear path for exploitation on sites with the Droip or Kirki integration active.
OpenCVE Enrichment