Sploitus

CVE-2026-12274

No indexed exploits for CVE-2026-12274 yet

The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.

Affected products
Tutor Lms
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.2% (8th percentile)
NVD status
Deferred
Published
2026-07-13
CVE-2026-12274 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-12274 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-12274 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.