Medium severity6.5NVD Advisory· Published Jul 13, 2026· Updated Jul 13, 2026
CVE-2026-12274
CVE-2026-12274
Description
The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.