What is CVE-2026-14310?
CVE-2026-14310 affects Tutor LMS WordPress plugin versions before 4.0.0, where the plugin fails to verify user access before processing Q&A threads. This allows authenticated subscribers with access to any single course to read unauthorized Q&A threads belonging to other courses.
Azərbaycanca: CVE-2026-14310, Tutor LMS WordPress plugin-unun 4.0.0-dan əvvəlki versiyalarında aşkarlanıb. Bu zəiflik autentifikasiya olunmuş abunəçi səviyyəli istifadəçilərə aid olmadıqları kursların Sual-Cavab mövzularına icazəsiz giriş imkanı verir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Tutor LMS plugin are affected by CVE-2026-14310?
This vulnerability affects versions of the Tutor LMS WordPress plugin before 4.0.0.
What level of authentication does an attacker need to exploit CVE-2026-14310?
An attacker needs to be an authenticated subscriber-level user with access to at least one course.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.