CVE-2026-14310
Received Received - Intake

Tutor LMS Q&A Thread Access Bypass Vulnerability

Vulnerability report for CVE-2026-14310, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tutor_lms tutor_lms to 4.0.0 (exc)
themeum tutor_lms to 4.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) in the Tutor LMS WordPress plugin before version 4.0.0. It allows authenticated users with subscriber-level access or higher to read Q&A threads from courses they are not enrolled in and inject replies into those threads by manipulating course and question IDs.

Detection Guidance

Check Tutor LMS plugin version with: wp plugin list | grep tutor_lms. If version is below 4.0.0, the system is vulnerable. Test by attempting to access Q&A threads of courses you are not enrolled in using manipulated IDs.

Impact Analysis

An attacker could access private Q&A content from courses they are not part of, potentially exposing sensitive information. They could also post unauthorized replies in other courses' Q&A threads, disrupting discussions or spreading misinformation.

Compliance Impact

This vulnerability could lead to unauthorized access to private course data, which may violate data protection regulations like GDPR or HIPAA if the exposed information includes personal or sensitive data. Compliance could be compromised due to unauthorized data exposure.

Mitigation Strategies

Update Tutor LMS plugin to version 4.0.0 or later immediately. If immediate update is not possible, restrict subscriber-level access to courses or disable Q&A functionality until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14310. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart