The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.
We have discovered 7,774 live websites that are affected by CVE-2026-12275.
| Product | |
| Category | Learning Management System |
| Vulnerable Domains | 7,774 live websites (88% of Tutor LMS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 124 versions ( 98% of all versions) |
| 2,139 websites | |
| 593 websites | |
| 409 websites | |
| 376 websites | |
| 371 websites | |
| 347 websites | |
| 327 websites | |
| 300 websites | |
| 230 websites | |
| 221 websites |
| .com | 3,611 websites |
| .org | 476 websites |
| .pl | 321 websites |
| .com.br | 265 websites |
| .de | 171 websites |
| .net | 161 websites |
| .it | 155 websites |
| .fr | 131 websites |
| .co.uk | 117 websites |
| .nl | 103 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | **,*** | ||
| ***************.org | **,*** | ||
| *************.org | **,*** | ||
| *****.com | ***,*** | ||
| **************.com | ***,*** | ||
| ***********.com | ***,*** | ||
| *********.es | ***,*** | ||
| ****************.com | ***,*** | ||
| *****.es | ***,*** | ||
| **************.com | ***,*** |
FAQ