CVE-2026-12273
The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one
CVSS
4.3
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jul 13, 2026 · Last modified: Jul 13, 2026
0.2%EPSS · 30 days0.3%
2026-08-082026-09-05
The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.
No related CVEs by CWE or product.