Description
The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tutor LMS WordPress plugin, before version 3.9.13, fails to enforce its core course handler checks within the Droip and Kirki page‑builder integration. As a result, authenticated users with subscriber‑level access can enroll in paid or private courses, view private course materials, and mark courses as completed without authorization. This allows a privileged user to bypass course enrollment restrictions and gain unauthorized access to confidential content, compromising the confidentiality and integrity of protected learning material. This vulnerability involves improper authorization checks (CWE-285) and information disclosure (CWE-200).

Affected Systems

All installations of the Tutor LMS plugin on WordPress sites using Droip or Kirki integration and running a version earlier than 3.9.13 are affected.

Risk and Exploitability

The vulnerability requires an authenticated subscriber account, which is common on learning platforms, making the attack vector straightforward. Because the flaw allows course enrollment and content access control bypass, it can be leveraged for data leakage and unauthorized completion marking. The CVSS score of 7.1 indicates high severity, while the EPSS score of <1% indicates that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, but the lack of core checks provides a clear path for exploitation on sites with the Droip or Kirki integration active.

Generated by OpenCVE AI on August 1, 2026 at 10:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tutor LMS to version 3.9.13 or later.
  • If an upgrade cannot be performed immediately, disable the Droip or Kirki integration for all courses to block the unauthorized enrollment path.
  • Restrict subscriber‑level role permissions to eliminate the ability to enroll in paid/private courses until the plugin is patched.

Generated by OpenCVE AI on August 1, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Fri, 17 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Mon, 13 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.
Title Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-13T15:46:49.109Z

Reserved: 2026-06-15T11:20:23.214Z

Link: CVE-2026-12275

cve-icon Vulnrichment

Updated: 2026-07-13T15:46:45.241Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses

No weakness.