CVE-2026-14306 MEDIUM

CVE-2026-14306: Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass

Vendor Unknown
Product Tutor LMS
Published August 6, 2026
Last update August 6, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses.

Explanation of Vulnerability in Simple Terms

02Summary

Tutor LMS versions before 3.9.14 contain an information disclosure vulnerability. An authenticated user with low privileges can read sensitive data they should not have access to. The vulnerability requires network access and does not require user interaction. Update to version 3.9.14 or later to resolve this issue.

What an attacker can do

03Attacker Capabilities

Read sensitive data they should not have access to.

Potential impact on your site

04Site Impact

Authenticated users can access confidential information beyond their permission level.

Conditions required to exploit

05Prerequisites

Attacker must be authenticated with a low-privilege account and have network access.

Key dates

06Disclosure timeline

August 6, 2026 CVE published