The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.
We have discovered 7,774 live websites that are affected by CVE-2026-12273.
| Product | |
| Category | Learning Management System |
| Vulnerable Domains | 7,774 live websites (88% of Tutor LMS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 124 versions ( 98% of all versions) |
| 2,139 websites | |
| 593 websites | |
| 409 websites | |
| 376 websites | |
| 371 websites | |
| 347 websites | |
| 327 websites | |
| 300 websites | |
| 230 websites | |
| 221 websites |
| .com | 3,611 websites |
| .org | 476 websites |
| .pl | 321 websites |
| .com.br | 265 websites |
| .de | 171 websites |
| .net | 161 websites |
| .it | 155 websites |
| .fr | 131 websites |
| .co.uk | 117 websites |
| .nl | 103 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | **,*** | ||
| ***************.org | **,*** | ||
| *************.org | **,*** | ||
| *****.com | ***,*** | ||
| **************.com | ***,*** | ||
| ***********.com | ***,*** | ||
| *********.es | ***,*** | ||
| ****************.com | ***,*** | ||
| *****.es | ***,*** | ||
| **************.com | ***,*** |
FAQ