AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14306

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Tutor LMS WordPress plugin prior to version 3.9.14 is vulnerable due to inadequate verification of user enrollment, enabling authenticated users with subscriber-level access or higher to access paid content from courses they are not enrolled in. This flaw poses a risk of unauthorized content exposure, potentially impacting the integrity of course offerings. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-14306
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
WordPress

Original NVD Description

The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses.