What the vulnerability does
01Description
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses.
Explanation of Vulnerability in Simple Terms
02Summary
Tutor LMS versions before 3.9.14 contain an information disclosure vulnerability. An authenticated user with low privileges can read sensitive data they should not have access to. The vulnerability requires network access and does not require user interaction. Update to version 3.9.14 or later to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data they should not have access to.
Potential impact on your site
04Site Impact
Authenticated users can access confidential information beyond their permission level.
Conditions required to exploit
05Prerequisites
Attacker must be authenticated with a low-privilege account and have network access.
Key dates
06Disclosure timeline
August 6, 2026
CVE published