Base de Datos de CVE /
CVE-2026-12274
CVE
CVE-2026-12274 — Tutor LMS – eLearning and online course solution [tutor] < 3.9.13
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-12274
|
Tutor LMS – eLearning and online course solution [tutor] < 3.9.13 |
Elusión de autorización mediante una clave controlada por el usuario |
Desconocido
|
< 3.9.13
|
3.9.13 |
2026-07-13 |
—
|
CVE-2026-12274
The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Escanea tu sitio WordPress gratis
Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.
Ver la página de seguridad completa de este plugin
Explorar la base de datos de CVE
Ver todos los hallazgos de seguridad