PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14306 Tutor LMS CVE debrief

The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content. Authenticated users with subscriber-level access and above who are enrolled in at least one course can view paid lesson, quiz, and assignment content belonging to other courses. This vulnerability affects users with low-level access, potentially allowing unauthorized access to course content. Verify enrollment verification in Tutor LMS plugin version 3.9.14 or earlier and restrict access controls. Evidence limits suggest verifying plugin version and restricting access controls. Further investigation is needed to determine the full scope of affected systems and potential impact.

Vendor
Tutor LMS
Product
Tutor LMS WordPress plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Users of the Tutor LMS WordPress plugin, particularly those with subscriber-level access or above, should verify their plugin version and restrict access controls to prevent unauthorized access to course content. Affected operators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Technical summary

The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The plugin's failure to verify enrollment can lead to unauthorized access to course content, potentially resulting in data breaches or other security incidents. Affected operators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Defensive priority

Authenticated users with low-level access can potentially access unauthorized course content. Verify enrollment verification in Tutor LMS plugin version 3.9.14 or earlier and restrict access controls.

Recommended defensive actions

  • Verify enrollment verification in Tutor LMS plugin version 3.9.14 or earlier
  • Restrict access controls to prevent unauthorized access to course content
  • Monitor for suspicious activity and update plugin to latest version
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of affected systems and potential impact. The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content. Authenticated users with subscriber-level access and above who are enrolled in at least one course can view paid lesson, quiz, and assignment content belonging to other courses. Evidence limits suggest verifying plugin version and restricting access controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:46.300Z and has not been modified since then. The NVD entry is currently Received.