SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14310

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Tutor LMS WordPress plugin prior to version 4.0.0 is vulnerable due to improper access control, allowing authenticated users with subscriber-level permissions to read and inject replies into Q&A threads of courses they do not own. This could lead to unauthorized information disclosure and potential misinformation within course discussions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14310
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%
WordPress

Original NVD Description

The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them.