CVE

CVE-2026-14310 — Tutor LMS – eLearning and online course solution [tutor] < 4.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14310 Tutor LMS – eLearning and online course solution [tutor] < 4.0.0 Authorization Bypass Through User-Controlled Key Unknown < 4.0.0 4.0.0 2026-07-27

CVE-2026-14310

Authenticated users with elevated privileges in Tutor LMS WordPress plugin versions prior to 4.0.0 can exploit a permissions oversight, enabling them to view and manipulate question-and-answer threads from unrelated courses. This vulnerability stems from inadequate access controls, allowing subscribers and higher-privileged users to access and alter Q&A content outside their own courses.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.