CVE-2026-14187: The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al
infovulnerability
security
Summary
The Tutor LMS WordPress plugin before version 4.0.6 has a security flaw where it doesn't properly check whether a user owns the content they're trying to access. This means any instructor can read private courses that belong to other instructors, even though they shouldn't have permission to do so.
Solution / Mitigation
Update the Tutor LMS WordPress plugin to version 4.0.6 or later.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
August 22, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14187
First tracked: August 22, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%