CVE-2026-12275

Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.


We have discovered 7,774 live websites that are affected by CVE-2026-12275.

Run a Free Instant Scan




Affected Software

Product  Tutor LMS
Category Learning Management System
Vulnerable Domains7,774 live websites (88% of Tutor LMS install base)
Vulnerable Versions
  • from 0 through 3.9.13
Vulnerable Versions Count124 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Jul 13, 2026
  • Updated - Jul 13, 2026

Credits

  • Dilovar Berdiev (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-12275
United States2,139 websites



Germany593 websites
Poland409 websites
France376 websites
Cyprus371 websites
India347 websites
GB327 websites
Brazil300 websites
Spain230 websites
Italy221 websites

Website Distribution by TLD

Number of websites using CVE-2026-12275
.com3,611 websites
.org476 websites
.pl321 websites
.com.br265 websites
.de171 websites
.net161 websites
.it155 websites
.fr131 websites
.co.uk117 websites
.nl103 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12275

Top websites that are affected by CVE-2026-12275. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
***************.org United States**,***
*************.org United States**,***
*****.com France***,***
**************.com Spain***,***
***********.com ***,***
*********.es Spain***,***
****************.com United States***,***
*****.es Spain***,***
**************.com United States***,***
See full domain list

FAQ

CVE-2026-12275 is Improper Authentication in Tutor LMS
A total of 7,774 websites have been identified as vulnerable to CVE-2026-12275, based on global website indexing conducted by WebTechSurvey.
The Tutor LMS is affected by the CVE-2026-12275 vulnerability.
Tutor LMS versions up to 3.9.13 are vulnerable to CVE-2026-12275.
CVE-2026-12275 is resolved in version 3.9.13 of Tutor LMS.