Description
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses.
Published: 2026-08-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tutor LMS WordPress plugin before 3.9.14 contains a flaw that fails to verify a user’s course enrollment when displaying protected lesson, quiz, or assignment content. Because of this, authenticated users who have subscriber or higher privileges and are enrolled in at least one course can view paid content from courses to which they are not enrolled. This allows inadvertent disclosure of copyrighted or monetized learning materials, which compromises confidentiality and potentially revenue models. The weakness is a form of improper access control (CWE‑639).

Affected Systems

Any WordPress site running Tutor LMS version earlier than 3.9.14 is affected. The vulnerability applies to all users with subscriber-level or higher roles who have enrolled in one or more courses, regardless of the courses they are not enrolled in. Failed enrollment checks occur across the plugin’s lesson, quiz, and assignment modules, exposing content belonging to other courses. Site administrators should verify whether their installations use a vulnerable plugin version, and identify users who may have obtained unauthorized access through this path.

Risk and Exploitability

The CVSS base score is 4.3, representing a moderate impact. EPSS is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated user with subscriber-level privileges; it requires that an attacker possess a legitimate WordPress account and have enrolled in at least one course. Once authenticated, the attacker can navigate to other courses’ content pages and bypass the enrollment check to retrieve paid lesson, quiz, or assignment resources. Because it is an insider‑type threat that relies on legitimate credentials, mitigating this flaw primarily depends on applying the vendor‑issued update or otherwise restricting access controls.

Generated by OpenCVE AI on August 13, 2026 at 10:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tutor LMS to version 3.9.14 or later
  • Reconfigure course access settings to ensure that paid content is only visible to users enrolled in that specific course
  • Revoke or limit subscriber-level roles for users who are not enrolled in any paid courses until the issue is fixed

Generated by OpenCVE AI on August 13, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-305

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Tutorlms
Tutorlms tutor Lms
Wordpress
Wordpress wordpress
Vendors & Products Tutorlms
Tutorlms tutor Lms
Wordpress
Wordpress wordpress

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-305

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and assignment content belonging to other courses.
Title Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Tutorlms Tutor Lms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T13:58:56.149Z

Reserved: 2026-07-01T11:15:14.129Z

Link: CVE-2026-14306

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-06T22:16:46.300

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-14306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key