NONE · 0

CVE-2026-14187

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses ...

Vulnerability Description

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

References

FAQ

What is CVE-2026-14187?

CVE-2026-14187 is a documented vulnerability. The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses ...

How severe is CVE-2026-14187?

CVSS scoring is not yet available for CVE-2026-14187. Check NVD for updates.

Is there a patch for CVE-2026-14187?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.