Sploitus

CVE-2026-14187

No indexed exploits for CVE-2026-14187 yet

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

Affected products
Tutor Lms
CVSS 3.1
2.7 LOW
EPSS
0.2% (12th percentile)
Weakness
CWE-639
NVD status
Deferred
Published
2026-08-22
CVE-2026-14187 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-14187 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-14187 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.