CVE-2026-40740: WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability
Published Apr 15, 2026
·Updated
Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7.
Affected Software
1 affected component
Themeum Tutor LMS<=3.9.7
Event History
Apr 15, 2026
CVE Published
via MITRE·10:21 AM
Data Sourced
via MITRE·10:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40740?
The severity of CVE-2026-40740 is considered high due to the broken access control vulnerability that allows unauthorized actions.
2
How do I fix CVE-2026-40740?
To fix CVE-2026-40740, update the Tutor LMS plugin to version 3.9.8 or later.
3
What types of attacks can occur due to CVE-2026-40740?
CVE-2026-40740 can allow attackers to exploit incorrectly configured access controls, potentially leading to unauthorized data access or modification.
4
Which versions of Tutor LMS are affected by CVE-2026-40740?
CVE-2026-40740 affects all versions of Tutor LMS from n/a through version 3.9.7.
5
Is there a patch available for CVE-2026-40740?
Yes, a patch is available in the updated version, which is 3.9.8 or later, for CVE-2026-40740.