Medium severity4.3NVD Advisory· Published Jul 13, 2026· Updated Jul 13, 2026
CVE-2026-12273
CVE-2026-12273
Description
The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.