cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, CVE-2026-14187

CVE, Research URL

CVE-2026-14187

Published on
Aug 22, 2026
Research Description
The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.
Affected versions
max 4.0.6.
Status
vulnerable