VYPR
Low severity2.7NVD Advisory· Published Aug 22, 2026· Updated Aug 26, 2026

CVE-2026-14187

CVE-2026-14187

Description

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1