What is CVE-2026-14306?
CVE-2026-14306 is an improper enrollment verification vulnerability in the Tutor LMS WordPress plugin. Before version 3.9.14, authenticated users with subscriber-level access enrolled in at least one course can view paid lesson, quiz, and assignment content without authorization. Updating the plugin to version 3.9.14 or later is necessary.
Azərbaycanca: CVE-2026-14306, Tutor LMS WordPress plaginində enrollment doğrulama çatışmazlığıdır. 3.9.14-dən əvvəlki versiyalarda, ən azı bir kursa yazılmış abunəçi səviyyəsində autentifikasiya olunmuş istifadəçilər, ödənişli dərs, quiz və tapşırıq məzmununa icazəsiz giriş əldə edə bilər. Plagin 3.9.14 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin does CVE-2026-14306 affect and what causes it?
This vulnerability affects the Tutor LMS WordPress plugin and is caused by improper enrollment verification.
To which version should the Tutor LMS plugin be updated to protect against CVE-2026-14306?
The plugin should be updated to version 3.9.14 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.