PatchSiren cyber security CVE debrief
CVE-2026-14306 Tutor LMS CVE debrief
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content. Authenticated users with subscriber-level access and above who are enrolled in at least one course can view paid lesson, quiz, and assignment content belonging to other courses. This vulnerability affects users with low-level access, potentially allowing unauthorized access to course content. Verify enrollment verification in Tutor LMS plugin version 3.9.14 or earlier and restrict access controls. Evidence limits suggest verifying plugin version and restricting access controls. Further investigation is needed to determine the full scope of affected systems and potential impact.
- Vendor
- Tutor LMS
- Product
- Tutor LMS WordPress plugin
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
Users of the Tutor LMS WordPress plugin, particularly those with subscriber-level access or above, should verify their plugin version and restrict access controls to prevent unauthorized access to course content. Affected operators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The plugin's failure to verify enrollment can lead to unauthorized access to course content, potentially resulting in data breaches or other security incidents. Affected operators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Defensive priority
Authenticated users with low-level access can potentially access unauthorized course content. Verify enrollment verification in Tutor LMS plugin version 3.9.14 or earlier and restrict access controls.
Recommended defensive actions
- Verify enrollment verification in Tutor LMS plugin version 3.9.14 or earlier
- Restrict access controls to prevent unauthorized access to course content
- Monitor for suspicious activity and update plugin to latest version
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of affected systems and potential impact. The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content. Authenticated users with subscriber-level access and above who are enrolled in at least one course can view paid lesson, quiz, and assignment content belonging to other courses. Evidence limits suggest verifying plugin version and restricting access controls.
Official resources
-
CVE-2026-14306 CVE record
CVE.org
-
CVE-2026-14306 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:46.300Z and has not been modified since then. The NVD entry is currently Received.