Junglewise Threat Intelligence

CVE-2026-12275: Themeum Tutor LMS auth bypass in Droip and Kirki integrations

CVE-2026-12275 · Severity: info · CVSS 5.4 · Published 2026-07-13

Technologies: Themeum Tutor LMS. Vendors: Themeum.

Executive brief

Tutor LMS is a popular WordPress plugin used to create and manage online courses. A security flaw in its integration with the Droip and Kirki page builders allows registered users (such as students) to bypass payment and enrollment restrictions. This means an unauthorized user could access paid or private course content for free and falsely mark courses as completed, potentially leading to revenue loss and unauthorized access to proprietary educational materials.

Technical details

An authentication bypass vulnerability exists in the Tutor LMS plugin's Droip and Kirki page-builder integrations. The software fails to replicate the enrollment, purchase, and private-course capability checks found in its core course handler within these specific integrations. An authenticated attacker with subscriber-level privileges can exploit this to enroll in paid or private courses, view restricted content, and manipulate course completion status. The vulnerability is present in versions prior to 3.9.13 on sites where the Droip or Kirki integrations are active. Users should update to version 3.9.13 or later to remediate the issue.

Affected products

  • Themeum Tutor LMS < 3.9.13

Timeline

  • 2026-06-22: disclosed: Initial public disclosure by researcher
  • 2026-06-22: patched: Fixed in version 3.9.13
  • 2026-07-13: advisory: NVD publication date

References

Related threats