cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, CVE-2026-12271

CVE, Research URL

CVE-2026-12271

Published on
Jul 13, 2026
Research Description
The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.
Affected versions
max 3.9.13.
Status
vulnerable