CVE-2026-14187: The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al | AI Sec Watch