Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 13, 2026
Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
CVE-2026-12274
Description
The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/c3d98ead-a4f4-48fd-bf9c-4fa91c5681d7/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.