Tutor LMS WordPress Plugin Droip/Kirki Integration Unauthorized Course Enrollment Vulnerability

Vulnerability

A vulnerability exists in the Tutor LMS WordPress plugin in versions prior to 3.9.13, specifically within the Droip and Kirki page-builder integrations. The plugin fails to apply the necessary checks for enrollment, purchase, and private-course capabilities that are enforced in its main course management system. As a result, authenticated users with subscriber-level access can unauthorizedly enroll in paid or private courses, access private course materials, and mark any course as completed, but only on sites where the Droip or Kirki integration is active.

Impact

Exploitation of this vulnerability allows for unauthorized enrollment in paid or private courses, access to private course content, and the ability to mark courses as completed.

Remediation

Users are advised to update the Tutor LMS WordPress plugin to version 3.9.13 or later.

Added: Jul 13, 2026, 7:29 AM
Updated: Jul 13, 2026, 7:29 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.4
remediation
7.7
relevance
9.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.