WordPress security changelog
MEDIUM CVE-2026-14306 Deferred

Tutor LMS permits cross-course paid-content access bypass

Tutor LMS before 3.9.14 does not correctly verify enrollment when authorizing protected course content. A logged-in Subscriber enrolled in at least one course can request paid lessons, quizzes and assignments from other courses without enrolling or purchasing them. The endpoint, action, course or content identifiers, authorization function and whether non-content actions are reachable are not disclosed.

CVE / CNA score 4.3 CVSS 3.1 · contact@wpscan.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Tutor LMS
Plugin slug
tutor
Affected
< 3.9.14
Safe version
3.9.14
Published
Aug 06, 2026
Weakness
CWE-639 — Authorization Bypass Through User-Controlled Key

This CVE was published Aug 06, 2026 and is one of 46 known issues for this plugin.

Update, patch or deactivate.

Update Tutor LMS to 3.9.14 or later. Review logs for low-privilege accounts requesting content outside their enrolled courses where available.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Primary and upstream sources