The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-22 06:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-14187
Mitre link : CVE-2026-14187
CVE.ORG link : CVE-2026-14187
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
