CVE-2026-14187: Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure via IDOR
Published Aug 22, 2026
·Updated
The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.
Affected Software
1 affected component
Tutor LMS WordPress plugin<4.0.6
Event History
Aug 22, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with the Tutor LMS instructor role can exploit it. The affected access is limited to private courses owned by other instructors.
2
What course data is exposed?
The issue allows an instructor to read the content of private courses belonging to other instructors.
3
Which deployments are affected?
Tutor LMS versions before 4.0.6 are affected. The available information does not state whether any particular default configuration changes exposure.